LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2017-0001: Microsoft Graphics Device Interface (GDI) Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 3, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 24, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2017-0001 to its Known Exploited Vulnerabilities catalog on Mar 3, 2022, with a federal patch deadline of Mar 24, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10…

CVE-2017-0001 is a privilege escalation vulnerability in the Microsoft Graphics Device Interface (GDI) component of several Windows client and server releases. A local user who can already run code on an affected system may be able to elevate privileges, which matters because it can turn a limited foothold into full administrative control and enable further persistence or lateral movement.

Defenders should treat this as a local elevation issue on the listed Windows platforms and confirm exact coverage and fixes against the vendor advisory before acting.

How it works

The vulnerability resides in the Graphics Device Interface (GDI), the Windows subsystem that handles drawing and graphics-related operations. Public detail on the exact weakness class is limited; CWE is not specified in the available record. In general terms for this class of flaw, an attacker who already has the ability to execute code as a standard user interacts with GDI in a way that causes it to mishandle privileged operations or memory, resulting in elevated privileges on the local system.

No remote exploitation path is described in the provided facts. Abuse therefore presupposes local access—via a prior compromise, malicious local account, or other means of running code on the host. Specifics of the trigger and any required conditions must be confirmed against the vendor advisory; do not assume particular APIs, file formats, or sequences beyond what Microsoft documents.

Am I affected? How to find it in your systems

GDI is a core component of the Windows operating system and is present on virtually every Windows workstation and server. The CISA summary lists the following as affected: Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607. Confirm the precise build and service-pack status of every Windows host against the vendor advisory, because later cumulative updates may already include the fix.

How to remediate

Apply the security updates issued by Microsoft for this vulnerability, following the vendor’s instructions exactly. CISA’s required action is to apply updates per vendor instructions. Prioritize domain-joined workstations, jump hosts, and any multi-user systems where local accounts or low-privilege code execution are more likely.

If you can't patch immediately

Compensating controls can reduce risk until the vendor update can be applied. These do not eliminate the vulnerability.

If your data may have been exposed

Actively exploited privilege-escalation vulnerabilities are commonly used after an initial foothold to deepen access and can lead to data theft or ransomware deployment; the available facts do not document ransomware use specifically for CVE-2017-0001. If you suspect compromise, isolate affected hosts, preserve forensic evidence, and follow your incident-response process. As a quick additional check, you can run a free exposure scan of your email addresses against known breach data to see whether credentials or personal information have appeared in prior public breaches.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Graphics Device Interface (GDI)
Added to CISA KEVMar 3, 2022
Federal patch deadlineMar 24, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities