cbcvebase.
CVE-2018-8440
published 2018-09-13

CVE-2018-8440: An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC), aka "Windows ALPC Elevation of…

PriorityP186high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2022-04-18
Exploited in the wild
EPSS
18.39%
96.9th percentile
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC), aka "Windows ALPC Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

Affected

45 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10_servers
microsoftwindows_10_servers
microsoftwindows_7
microsoftwindows_7
microsoftwindows_8.1
microsoftwindows_8.1
microsoftwindows_rt_8.1
microsoftwindows_server_2008
microsoftwindows_server_2008
microsoftwindows_server_2008
microsoftwindows_server_2008
microsoftwindows_server_2008
microsoftwindows_server_2008
microsoftwindows_server_2008_r2
microsoftwindows_server_2008_r2

Detection & IOCsextracted from sources · hover to see the quote

pathc:\windows\tasks
filenamePrintConfig.dll
path%windir%\system32\driverstor\filerepository\prnms003*
  • Monitor for hardlink creation in c:\windows\tasks pointing to files outside the tasks directory — a key step in exploiting the ALPC Task Scheduler LPE.
  • Alert on unexpected modification or overwrite of PrintConfig.dll under %windir%\system32\driverstor\filerepository\prnms003*, as the Metasploit exploit overwrites this DLL during exploitation.
  • Monitor for calls to the ALPC endpoint method SchRpcSetSecurity in the Task Scheduler service (schedsvc.dll / taskschd) from non-SYSTEM, non-administrative processes, which is the core exploitation primitive.
  • Track low-privilege processes that suddenly spawn children with SYSTEM-level privileges — indicative of successful LPE via CVE-2018-8440 exploitation.
  • ·The Metasploit module targets Windows 10 Pro x64 specifically; effectiveness against other Windows versions (7, 8.1, Server 2008/2012/2016) should be validated separately.
  • ·The exploit requires the attacker to already have the ability to create files in c:\windows\tasks (i.e., a standard user account), not unauthenticated remote access.

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vulncheck7.8HIGH
cisa7.8HIGH
vendor_msrc7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.