CVE-2018-8397: Microsoft Windows 7
High severity, CVSS 8.8. EPSS: 67.9% chance of exploitation in the next 30 days.
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka "GDI+ Remote Code Execution Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2.
Affected products
- Microsoft Windows 7: affected versions not specified
- Microsoft Windows Server 2008: affected versions not specified; version r2 only
Published 2018-08-15. Last modified 2026-06-17.