PatchSiren cyber security CVE debrief
CVE-2019-0903 Microsoft CVE debrief
CVE-2019-0903 is a Microsoft Graphics Device Interface (GDI) remote code execution vulnerability that CISA has listed in its Known Exploited Vulnerabilities catalog. Because it appears in the KEV catalog, defenders should treat it as actively relevant to patch management and exposure reduction. The supplied CISA entry says to apply updates per vendor instructions.
- Vendor
- Microsoft
- Product
- Graphics Device Interface (GDI)
- CVSS
- Unknown
- CISA KEV
- Listed
- Original CVE published
- 2022-03-25
- Original CVE updated
- 2022-03-25
- Advisory published
- 2022-03-25
- Advisory updated
- 2022-03-25
Who should care
Windows administrators, endpoint security teams, vulnerability management teams, and incident responders responsible for Microsoft systems that rely on Graphics Device Interface (GDI).
Technical summary
The supplied source corpus identifies CVE-2019-0903 as a Microsoft GDI remote code execution vulnerability and confirms it is KEV-listed by CISA. The available evidence does not include exploit mechanics, affected build ranges, or remediation specifics beyond CISA’s instruction to apply updates per vendor guidance.
Defensive priority
High. CISA placed this CVE in the Known Exploited Vulnerabilities catalog and assigned a due date of 2022-04-15, which makes timely remediation a priority even without additional technical details in the provided corpus.
Recommended defensive actions
- Apply Microsoft security updates that address CVE-2019-0903, following vendor instructions.
- Verify deployment across all managed Windows endpoints and servers that may use Microsoft GDI components.
- Track remediation status in vulnerability management tooling and escalate any systems that remain unpatched past policy deadlines.
- Use the CISA KEV listing to prioritize exposed or business-critical assets for faster validation and rollback planning if needed.
Evidence notes
Evidence is limited to the supplied CISA KEV source item metadata and the official CVE/NVD record links. The corpus confirms the CVE identifier, Microsoft as the vendor, the product name Graphics Device Interface (GDI), KEV status, dateAdded 2022-03-25, dueDate 2022-04-15, and the required action to apply updates per vendor instructions. No exploit details, affected-version ranges, or CVSS data were provided in the corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2019-0903 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2019-0903
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2019-0903 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2019-0903
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
-
CISA Known Exploited Vulnerabilities catalog
Publisher, destination, and source semantics verified
URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
cisa_kev
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.