CVE-2018-8589 KEV
7.8
HIGH · CVSS 3.1 · EPSS 3% (pctl 87)
Patch first
On CISA KEV — known exploited in the wild, due 2022-06-13.
Description
An elevation of privilege vulnerability exists when Windows improperly handles calls to Win32k.sys, aka "Windows Win32k Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2.
Scoring
| CVSS | 7.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.02% — more likely to be exploited than 87% of all CVEs |
| On CISA KEV | yes — remediate by 2022-06-13 |
| Public exploit | none known |
| Published | 2018-11-14 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Microsoft Win32k Privilege Escalation Vulnerability |
|---|---|
| Added | 2022-05-23 |
| Due | 2022-06-13 |
| Vendor / product | Microsoft / Win32k |
| Ransomware use | none reported |
Affected (2)
| Vendor | Product |
|---|---|
| microsoft | windows 7 |
| microsoft | windows server 2008 |
References
- http://www.securityfocus.com/bid/105796
- http://www.securitytracker.com/id/1042140
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8589
- http://www.securityfocus.com/bid/105796
- http://www.securitytracker.com/id/1042140
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8589
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-8589
→ the Explorer · watch your stack · NVD