Can you please clarify whether or not this specific patch is user mode or kernel mode? @johntb86 mentioned GDI is split and this is the user mode part.
Our micropatch (7 of them, really, for 4 different Windows OS versions) for CVE-2017-0038 is user-mode. As are currently all our micropatches. Processes using gdi32.dll do not need to be relaunched to have it applied.