PatchSiren

PatchSiren cyber security CVE debrief

CVE-2019-0903 Microsoft CVE debrief

CVE-2019-0903 is a Microsoft Graphics Device Interface (GDI) remote code execution vulnerability that CISA has listed in its Known Exploited Vulnerabilities catalog. Because it appears in the KEV catalog, defenders should treat it as actively relevant to patch management and exposure reduction. The supplied CISA entry says to apply updates per vendor instructions.

Vendor
Microsoft
Product
Graphics Device Interface (GDI)
CVSS
Unknown
CISA KEV
Listed
Original CVE published
2022-03-25
Original CVE updated
2022-03-25
Advisory published
2022-03-25
Advisory updated
2022-03-25

Who should care

Windows administrators, endpoint security teams, vulnerability management teams, and incident responders responsible for Microsoft systems that rely on Graphics Device Interface (GDI).

Technical summary

The supplied source corpus identifies CVE-2019-0903 as a Microsoft GDI remote code execution vulnerability and confirms it is KEV-listed by CISA. The available evidence does not include exploit mechanics, affected build ranges, or remediation specifics beyond CISA’s instruction to apply updates per vendor guidance.

Defensive priority

High. CISA placed this CVE in the Known Exploited Vulnerabilities catalog and assigned a due date of 2022-04-15, which makes timely remediation a priority even without additional technical details in the provided corpus.

Recommended defensive actions

  • Apply Microsoft security updates that address CVE-2019-0903, following vendor instructions.
  • Verify deployment across all managed Windows endpoints and servers that may use Microsoft GDI components.
  • Track remediation status in vulnerability management tooling and escalate any systems that remain unpatched past policy deadlines.
  • Use the CISA KEV listing to prioritize exposed or business-critical assets for faster validation and rollback planning if needed.

Evidence notes

Evidence is limited to the supplied CISA KEV source item metadata and the official CVE/NVD record links. The corpus confirms the CVE identifier, Microsoft as the vendor, the product name Graphics Device Interface (GDI), KEV status, dateAdded 2022-03-25, dueDate 2022-04-15, and the required action to apply updates per vendor instructions. No exploit details, affected-version ranges, or CVSS data were provided in the corpus.

Sources and references

Verified primary and authoritative sources

  • CVE-2019-0903 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2019-0903

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2019-0903 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2019-0903

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

  • CISA Known Exploited Vulnerabilities catalog

    Publisher, destination, and source semantics verified

    URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

    Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json

    cisa_kev

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.