cbcvebase.
CVE-2018-8120
published 2018-05-09

CVE-2018-8120: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of…

PriorityP187high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2022-04-05
Exploited in the wild
EPSS
73.72%
99.4th percentile
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2. This CVE ID is unique from CVE-2018-8124, CVE-2018-8164, CVE-2018-8166.

Affected

45 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10_servers
microsoftwindows_10_servers
microsoftwindows_7
microsoftwindows_7
microsoftwindows_8.1
microsoftwindows_8.1
microsoftwindows_rt_8.1
microsoftwindows_server_2008
microsoftwindows_server_2008

Detection & IOCsextracted from sources · hover to see the quote

hash3039208b2a34bb2e71bc6a77ae3be2fa588abd359fdb0068253739f3839f3425
hash1aa1df57f786224f4997f1d6284a123176291f3f3d43bc4b942ae423c58cc356
hash36725374d7ec66c9876eb1d5edc2a5889643e01dbd0ac7a6705babbc3c3ea6a9
hashdb7c4a360b460a13148d6e5fff530afaa0fa161959166cdab342d0aa9760ba68
hashf09c502f4b5862641b3c3eff19ae96d949fab465b3fddd1888fe945817c9e2fd
hash4b672deae5c1231ea20ea70b0bf091164ef0b939e2cf4d142d31916a169e8e01
urlhttp://wpad[.]id/wpad[.]dat
urlhttp://9kf[.]me/in[.]php?id=1
urlhttp://2kf[.]me/in[.]php
urlhttp://6kf[.]me/in[.]php
urlhttp://9kf[.]me/in[.]php
domainupdate.7h4uk[.]com
ip185.128.43.62
domaininfo.7h4uk[.]com
hashAEEB46A88C9A37FA54CA2B64AE17F248
hash4FE2DE6FBB278E56C23E90432F21F6C8
hash71404815F6A0171A29DE46846E78A079
hash81E214A4120A4017809F5E7713B7EAC8
filenamewinupdate64.log
filenamesysupdate.log
filenamejava-log-9527.log
  • PurpleFox exploit chain exploiting CVE-2018-8120 delivers payloads via WPAD abuse; monitor for DNS/HTTP requests to wpad.id and subsequent MSI/PowerShell staging activity.
  • ScarCruft (APT group) uses CVE-2018-8120 to bypass Windows UAC and execute next-stage payloads with elevated privileges, delivered via spear-phishing and known exploits.
  • PowerGhost miner uses CVE-2018-8120 (32- or 64-bit exploit) for privilege escalation alongside MS16-032 and MS15-051; spreads via WMI and EternalBlue.
  • ·The Falcon Sandbox analysis of the CVE-2018-8120 exploit was performed specifically on Windows 7 32-bit SP1 Build 7601 with Adobe Acrobat Reader DC Continuous Release 2018.009.20044; results may differ on other OS/Reader versions.

CVSS provenance

nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vulncheck7.0HIGH
cisa7.0HIGH
vendor_msrc7.0HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.