CVE-2018-8440
published 2018-09-13CVE-2018-8440: An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC), aka "Windows ALPC Elevation of…
PriorityP186high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2022-04-18
Exploited in the wild
EPSS
18.39%
96.9th percentile
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC), aka "Windows ALPC Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Affected
45 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_servers | — | — |
| microsoft | windows_10_servers | — | — |
| microsoft | windows_7 | — | — |
| microsoft | windows_7 | — | — |
| microsoft | windows_8.1 | — | — |
| microsoft | windows_8.1 | — | — |
| microsoft | windows_rt_8.1 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2 | — | — |
| microsoft | windows_server_2008_r2 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for hardlink creation in c:\windows\tasks pointing to files outside the tasks directory — a key step in exploiting the ALPC Task Scheduler LPE. ↗
- →Alert on unexpected modification or overwrite of PrintConfig.dll under %windir%\system32\driverstor\filerepository\prnms003*, as the Metasploit exploit overwrites this DLL during exploitation. ↗
- →Monitor for calls to the ALPC endpoint method SchRpcSetSecurity in the Task Scheduler service (schedsvc.dll / taskschd) from non-SYSTEM, non-administrative processes, which is the core exploitation primitive. ↗
- →Track low-privilege processes that suddenly spawn children with SYSTEM-level privileges — indicative of successful LPE via CVE-2018-8440 exploitation. ↗
- ·The Metasploit module targets Windows 10 Pro x64 specifically; effectiveness against other Windows versions (7, 8.1, Server 2008/2012/2016) should be validated separately. ↗
- ·The exploit requires the attacker to already have the ability to create files in c:\windows\tasks (i.e., a standard user account), not unauthenticated remote access. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vulncheck7.8HIGH
cisa7.8HIGH
vendor_msrc7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jw7v-w46m-p6pp: An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC), aka "Windows ALPC Elevat
ghsa_unreviewed·2022-05-13
CVE-2018-8440 [HIGH] GHSA-jw7v-w46m-p6pp: An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC), aka "Windows ALPC Elevat
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC), aka "Windows ALPC Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
VulnCheck
Microsoft Windows Privilege Escalation Vulnerability
vulncheck·2018·CVSS 7.8
CVE-2018-8440 [HIGH] Microsoft Windows Privilege Escalation Vulnerability
Microsoft Windows Privilege Escalation Vulnerability
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC).
Affected: Microsoft Windows
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://www.welivesecurity.com/2018/09/05/powerpool-malware-exploits-zero-day-vulnerability/; https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2018-Sep; https://www.mcafee.com/blogs/other-blogs/mcafee-labs/rapidly-evolving-ransomware-gandcrab-version-5-partners-with-crypter-service-for-obfuscation/; https://web.archive.org/web/20220227045141/https://risksense.com/wp-content/uploads/2019/09/RiskSense-Spotlight-Report-Ransomware.pdf; https://www.cisa.gov/sites/default/fi
CISA
Microsoft Windows Privilege Escalation Vulnerability
cisa·2022-03-28·CVSS 7.8
CVE-2018-8440 [HIGH] Microsoft Windows Privilege Escalation Vulnerability
Vulnerability: Microsoft Windows Privilege Escalation Vulnerability
Affected: Microsoft Windows
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC).
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2018-8440
Remediation Due Date: 2022-04-18
Microsoft
Windows ALPC Elevation of Privilege Vulnerability
vendor_msrc·2018-09-11·CVSS 7.8
CVE-2018-8440 [HIGH] Windows ALPC Elevation of Privilege Vulnerability
Windows ALPC Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC).
An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control over an affected system.
The update addresses the vulnerability by correcting how Windows handles calls to ALPC.
Microsoft Windows: Microsoft Windows
Issuing CNA: Mi
No detection rules found.
Securelist
IT threat evolution Q3 2018. Statistics
blogs_securelist·2018-11-12
IT threat evolution Q3 2018. Statistics
Table of Contents
Q3 figures
Mobile threats
Q3 events
Mobile threat statistics
Distribution of detected mobile apps by type
Geography of mobile threats
Mobile banking Trojans
Mobile ransomware Trojans
Attacks on IoT devices
Telnet attacks
Financial threats
Q3 events
Financial threat statistics
Geography of attacks
Cryptoware programs
Q3 events
Statistics
Number of new modifications
Number of users attacked by Trojan cryptors
Geography of attacks
Cryptominers
Statistics
Number of new modifications
Number of users attacked by cryptominers
Geography of attacks
Vulnerable apps used by cybercriminals
Attacks via web resources
Countries where online resources are seeded with malware
Countries where users faced the greatest risk of online infection
Local threats
Cou
Securelist
IT threat evolution Q3 2018. Statistics
blogs_securelist·2018-11-12
IT threat evolution Q3 2018. Statistics
Table of Contents
- Q3 figures
- Mobile threats
- Attacks on IoT devices
- Financial threats
- Cryptoware programs
- Cryptominers
- Vulnerable apps used by cybercriminals
- Attacks via web resources
- Local threats
Authors
- Victor Chebyshev
- Fedor Sinitsyn
- Denis Parinov
- Oleg Kupreev
- Evgeny Lopatin
- Alexander Liskin
These statistics are based on detection verdicts of Kaspersky Lab products received from users who consented to provide statistical data.
## Q3 figures
According to Kaspersky Security Network:
- Kaspersky Lab solutions blocked 947,027,517 attacks launched from online resources located in 203 countries.
- 246,695,333 unique URLs were recognized as malicious by Web Anti-Virus components.
- Attempted infections by malware designed to steal money via online access to
Trendmicro
September Patch Tuesday: Windows Fixes ALPC Bug
blogs_trendmicro·2018-09-12·CVSS 7.8
CVE-2018-8440 [HIGH] September Patch Tuesday: Windows Fixes ALPC Bug
Exploits y vulnerabilidades
## September Patch Tuesday: Windows Fixes ALPC Bug
September’s Patch Tuesday provides a security patch for CVE-2018-8440, an elevation of privilege vulnerability that occurs when Windows incorrectly handles calls to the Advanced Local Procedure Call (ALPC) interface.
By: Trend Micro Sep 12, 2018 Read time: ( words)
Save to Folio
September’s Patch Tuesday provides a security patch for CVE-2018-8440 , an elevation of privilege vulnerability that occurs when Windows incorrectly handles calls to the Advanced Local Procedure Call (ALPC) interface. This bug allows threat actors to run code with administrative privileges, install programs, or even create new accounts with full user rights. This bug’s source code has been publicly disclosed as of August 27 via Twit
Trendmicro
September Patch Tuesday: Windows Fixes ALPC Bug
blogs_trendmicro·2018-09-12·CVSS 7.8
CVE-2018-8440 [HIGH] September Patch Tuesday: Windows Fixes ALPC Bug
Exploits & Vulnerabilities
# September Patch Tuesday: Windows Fixes ALPC Bug
September’s Patch Tuesday provides a security patch for CVE-2018-8440, an elevation of privilege vulnerability that occurs when Windows incorrectly handles calls to the Advanced Local Procedure Call (ALPC) interface.
By: Trend Micro
2018/09/12
Read time: ( words)
Save to Folio
September’s Patch Tuesday provides a security patch for CVE-2018-8440, an elevation of privilege vulnerability that occurs when Windows incorrectly handles calls to the Advanced Local Procedure Call (ALPC) interface. This bug allows threat actors to run code with administrative privileges, install programs, or even create new accounts with full user rights. This bug’s source code has been publicly disclosed as of August 27 via Twitter
Trendmicro
September Patch Tuesday: Windows Fixes ALPC Bug
blogs_trendmicro·2018-09-12·CVSS 7.8
CVE-2018-8440 [HIGH] September Patch Tuesday: Windows Fixes ALPC Bug
Exploits & Vulnerabilities
## September Patch Tuesday: Windows Fixes ALPC Bug
September’s Patch Tuesday provides a security patch for CVE-2018-8440, an elevation of privilege vulnerability that occurs when Windows incorrectly handles calls to the Advanced Local Procedure Call (ALPC) interface.
By: Trend Micro Sep 12, 2018 Read time: ( words)
Save to Folio
September’s Patch Tuesday provides a security patch for CVE-2018-8440 , an elevation of privilege vulnerability that occurs when Windows incorrectly handles calls to the Advanced Local Procedure Call (ALPC) interface. This bug allows threat actors to run code with administrative privileges, install programs, or even create new accounts with full user rights. This bug’s source code has been publicly disclosed as of August 27 via Twitt
Trendmicro
September Patch Tuesday: Windows Fixes ALPC Bug
blogs_trendmicro·2018-09-12·CVSS 7.8
CVE-2018-8440 [HIGH] September Patch Tuesday: Windows Fixes ALPC Bug
Exploits & Vulnerabilities
## September Patch Tuesday: Windows Fixes ALPC Bug
September’s Patch Tuesday provides a security patch for CVE-2018-8440, an elevation of privilege vulnerability that occurs when Windows incorrectly handles calls to the Advanced Local Procedure Call (ALPC) interface.
By: Trend Micro 2018/09/12 Read time: ( words)
Save to Folio
September’s Patch Tuesday provides a security patch for CVE-2018-8440 , an elevation of privilege vulnerability that occurs when Windows incorrectly handles calls to the Advanced Local Procedure Call (ALPC) interface. This bug allows threat actors to run code with administrative privileges, install programs, or even create new accounts with full user rights. This bug’s source code has been publicly disclosed as of August 27 via Twitter
Trendmicro
September Patch Tuesday: Windows Fixes ALPC Bug
blogs_trendmicro·2018-09-12·CVSS 7.8
CVE-2018-8440 [HIGH] September Patch Tuesday: Windows Fixes ALPC Bug
Ausnutzung von Schwachstellen
## September Patch Tuesday: Windows Fixes ALPC Bug
September’s Patch Tuesday provides a security patch for CVE-2018-8440, an elevation of privilege vulnerability that occurs when Windows incorrectly handles calls to the Advanced Local Procedure Call (ALPC) interface.
By: Trend Micro Sep 12, 2018 Read time: ( words)
Save to Folio
September’s Patch Tuesday provides a security patch for CVE-2018-8440 , an elevation of privilege vulnerability that occurs when Windows incorrectly handles calls to the Advanced Local Procedure Call (ALPC) interface. This bug allows threat actors to run code with administrative privileges, install programs, or even create new accounts with full user rights. This bug’s source code has been publicly disclosed as of August 27 via Tw
Talos
Microsoft Patch Tuesday - September 2018
blogs_talos·2018-09-11·CVSS 8.4
[HIGH] Microsoft Patch Tuesday - September 2018
Microsoft released its monthly set of security updates today for a variety of its products that address a variety of bugs. The latest Patch Tuesday covers 61 vulnerabilities, 17 of which are rated "critical," 43 that are rated "important" and one that is considered to have "moderate" severity.
The advisories cover bugs in the Internet Explorer web browser, Jet Database Engine and the Chakra scripting engine, among other products and software.
This update also includes two critical advisories, one of which covers security updates to Adobe Flash, and another that deals with a denial-of-service vulnerability in the Microsoft Windows operating system.
## Critical vulnerabilitiesMicrosoft released coverage for 17 critical bugs. Cisco Talos believes 16 of these are of special importance and n
Krebs
Patch Tuesday, September 2018 Edition
blogs_krebs·2018-09-11·CVSS 7.5
[HIGH] Patch Tuesday, September 2018 Edition
Adobe and Microsoft today each released patches to fix serious security holes in their software. Adobe pushed out a new version of its beleaguered Flash Player browser plugin. Redmond issued updates to address at least 61 distinct vulnerabilities in Microsoft Windows and related programs, including several flaws that were publicly detailed prior to today and one “zero-day” bug in Windows that is already being actively exploited by attackers.
As per usual, the bulk of the fixes from Microsoft tackle security weaknesses in the company’s Web browsers, Internet Explorer and Edge . Patches also are available for Windows, Office , Sharepoint , and the .NET Framework , among other components.
Of the 61 bugs fixed in this patch batch, 17 earned Microsoft’s “critical” rating, meaning malware or m
Krebs
Patch Tuesday, September 2018 Edition
blogs_krebs·2018-09-11·CVSS 7.5
[HIGH] Patch Tuesday, September 2018 Edition
Adobe and Microsoft today each released patches to fix serious security holes in their software. Adobe pushed out a new version of its beleaguered Flash Player browser plugin. Redmond issued updates to address at least 61 distinct vulnerabilities in Microsoft Windows and related programs, including several flaws that were publicly detailed prior to today and one “zero-day” bug in Windows that is already being actively exploited by attackers.
Of the 61 bugs fixed in this patch batch, 17 earned Microsoft’s “critical” rating, meaning malware or miscreants could use them to break into Windows computers with little or no help from users.
The zero-day flaw, CVE-2018-8440, affects Microsoft operating systems from Windows 7 through Windows 10 and allows a program launched by a restricted Windows
Talos
Microsoft Patch Tuesday - September 2018
blogs_talos·2018-09-11·CVSS 8.4
[HIGH] Microsoft Patch Tuesday - September 2018
## Microsoft Patch Tuesday - September 2018
Microsoft released its monthly set of security updates today for a variety of its products that address a variety of bugs. The latest Patch Tuesday covers 61 vulnerabilities, 17 of which are rated "critical," 43 that are rated "important" and one that is considered to have "moderate" severity.
The advisories cover bugs in the Internet Explorer web browser, Jet Database Engine and the Chakra scripting engine, among other products and software.
This update also includes two critical advisories, one of which covers security updates to Adobe Flash, and another that deals with a denial-of-service vulnerability in the Microsoft Windows operating system.
## Critical vulnerabilities Microsoft released coverage for 17 critical bugs. Cisco Talos believ
Tenable
Windows Task Scheduler Zero-Day Exploit Available in the Wild: Caution Urged
blogs_tenable·2018-08-28·CVSS 7.8
CVE-2018-8440 [HIGH] Windows Task Scheduler Zero-Day Exploit Available in the Wild: Caution Urged
Blog / Cyber Exposure Alerts
Subscribe
# Windows Task Scheduler Zero-Day Exploit Available in the Wild: Caution Urged
Paul Davis
August 28, 2018
2 Min Read
Updated September 11: Microsoft released the patch for this vulnerability (CVE-2018-8440) today as part of its monthly security update known as Patch Tuesday. Customers are advised to apply this security update as soon as possible.
Updated September 5: Public exploits of this vulnerability have been seen by researchers at ESET. The Solution section of the CERT page offers the best known workaround until Microsoft releases a patch, which is planned for September 11.
## Background
On August 27, a security researcher made waves by releasing a working exploit on Github for a previously unknown, serious local privilege escalation (LP
Tenable
Windows Task Scheduler Zero-Day Exploit Available in the Wild: Caution Urged
blogs_tenable·2018-08-28
Windows Task Scheduler Zero-Day Exploit Available in the Wild: Caution Urged
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Zscaler
Zscaler protects against 10 new vulnerabilities for Chakra Scripting Engine, Internet Explorer, MS XML, Windows & Microsoft Edge. | Zscaler
blogs_zscaler·CVSS 7.5
[HIGH] Zscaler protects against 10 new vulnerabilities for Chakra Scripting Engine, Internet Explorer, MS XML, Windows & Microsoft Edge. | Zscaler
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
arXiv
Technical Report -- Expected Exploitability: Predicting the Development of Functional Vulnerability Exploits
arxiv_fulltext·2022-02-03
Technical Report -- Expected Exploitability: Predicting the Development of Functional Vulnerability Exploits
Octavian Suciu,
Connor Nelson ,
Zhuoer Lyu ,
Tiffany Bao ,
Tudor Dumitras
University of Maryland, College Park
State University
comment
\@IEEEpubidpullup6.5
Network and Distributed Systems Security (NDSS) Symposium 2020
23-26 February 2020, San Diego, CA, USA
ISBN 1-891562-61-4
https://dx.doi.org/10.14722/ndss.2020.23xxx
www.ndss-symposium.org
[ ]
comment
empty
## Abstract
Assessing the exploitability of software vulnerabilities at the time of disclosure is difficult and error-prone, as features extracted via technical analysis by existing metrics are poor predictors for exploit development.
Moreover, exploitability assessments suffer from a class bias because ``not exploitable'' labels could be inaccurate.
To overcome these challenges, we propose a new metric, called Expecte
arXiv
Cyberthreat Detection from Twitter using Deep Neural Networks
arxiv_fulltext·2019-04-01
Cyberthreat Detection from Twitter using Deep Neural Networks
Nuno Dionísio,
Fernando Alves,
Pedro M. Ferreira and
Alysson Bessani
LASIGE, Faculdade de Ciências, Universidade de Lisboa
Lisboa 1749-016, Portugal
Email: \ndionisio, falves\@lasige.di.fc.ul.pt,
\pmf, anbessani\@ciencias.ulisboa.pt
## Abstract
To be prepared against cyberattacks, most organizations resort to security information and event management systems to monitor their infrastructures.
These systems depend on the timeliness and relevance of the latest updates, patches and threats provided by cyberthreat intelligence feeds.
Open source intelligence platforms, namely social media networks such as Twitter, are capable of aggregating a vast amount of cybersecurity-related sources.
To process such information streams, we require scalable and efficient tools capable of identifying and
http://www.securityfocus.com/bid/105153http://www.securitytracker.com/id/1041578https://blog.0patch.com/2018/08/how-we-micropatched-publicly-dropped.htmlhttps://blog.0patch.com/2018/09/comparing-our-micropatch-with.htmlhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8440http://www.securityfocus.com/bid/105153http://www.securitytracker.com/id/1041578https://blog.0patch.com/2018/08/how-we-micropatched-publicly-dropped.htmlhttps://blog.0patch.com/2018/09/comparing-our-micropatch-with.htmlhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8440https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-8440
2018-09-13
Published
2022-03-28
Added to CISA KEV
Exploited in the wild