CVE-2018-8453
published 2018-10-10CVE-2018-8453: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of…
PriorityP188high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2022-07-21
Exploited in the wild
EPSS
69.83%
99.3th percentile
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Affected
49 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_servers | — | — |
| microsoft | windows_10_servers | — | — |
| microsoft | windows_7 | — | — |
| microsoft | windows_7 | — | — |
| microsoft | windows_8.1 | — | — |
| microsoft | windows_8.1 | — | — |
| microsoft | windows_rt_8.1 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect exploitation of CVE-2018-8453 by monitoring for usermode hooks placed on KernelCallbackTable entries for fnDWORD, fnNCDESTROY, and fnINLPCREATESTRUCT — a hallmark of this exploit's setup phase. ↗
- →Monitor for Token-stealing shellcode patterns that swap the current process Token with the SYSTEM EPROCESS token following a win32k.sys Use-After-Free exploitation sequence. ↗
- →Hunt for malware payloads encrypted with AES-256-CBC keyed on the SHA-1 of the SMBIOS UUID, stored as a randomly named file in the Windows directory — a persistence technique used by the FruityArmor implant delivered via this exploit. ↗
- →Detect anomalous use of Microsoft BITS (Background Intelligent Transfer Service) for C2 communications, as the FruityArmor implant delivered via this exploit uses BITS as its C2 channel. ↗
- →Flag processes that store a payload as a randomly named file in the Windows directory and locate it by comparing a hash of every filename in that directory — indicative of the FruityArmor loader behavior. ↗
- →In Sodin/REvil samples, check the configuration block field 'exp' to determine whether the CVE-2018-8453 exploit is enabled; presence of this field set to true indicates active privilege escalation via win32k.sys. ↗
- →Kaspersky AV verdicts HEUR:Exploit.Win32.Generic, HEUR:Trojan.Win32.Generic, and PDM:Exploit.Win32.Generic are associated with artifacts from CVE-2018-8453 exploitation campaigns. ↗
- ·The FruityArmor implant payload is encrypted with AES-256-CBC using the SHA-1 of the victim machine's SMBIOS UUID as the key, making static decryption impossible without the specific victim's UUID — sandbox detonation on the original victim hardware or UUID extraction is required. ↗
- ·The exploit's heap spray procedure varies by Windows version; it includes five separate spray functions, with the Windows 10 RS4 variant using bitmap objects of varying sizes to exhaust the Low Fragmentation Heap allocator — detection logic must account for version-specific spray patterns. ↗
- ·Sodin/REvil's CVE-2018-8453 exploit is embedded in a 32-bit executable and uses the Heaven's Gate technique to execute 64-bit shellcode; analysis tools that do not handle mixed 32/64-bit code may miss the exploit logic. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vulncheck7.8HIGH
cisa7.8HIGH
vendor_msrc7.0HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8587-44mr-xf6j: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation
ghsa_unreviewed·2022-05-13
CVE-2018-8453 [HIGH] CWE-404 GHSA-8587-44mr-xf6j: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
VulnCheck
Microsoft Win32k Privilege Escalation Vulnerability
vulncheck·2018·CVSS 7.8
CVE-2018-8453 [HIGH] CWE-404 Microsoft Win32k Privilege Escalation Vulnerability
Microsoft Win32k Privilege Escalation Vulnerability
Microsoft Windows Win32k contains a vulnerability that allows an attacker to escalate privileges.
Affected: Microsoft Win32k
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2018-Oct; https://securelist.com/zero-day-in-windows-kernel-transaction-manager-cve-2018-8611/89253/; https://securelist.com/cve-2019-0797-zero-day-vulnerability/89885/; https://digital.nhs.uk/cyber-alerts/2019/cc-3044; https://www.cyber.nj.gov/threat-center/threat-profiles/ransomware-variants/sodinokibi; https://web.archive.org/web/20220227045141/https://riskse
VulnCheck
Adobe Flash Player Stack-based Buffer Overflow Vulnerability
vulncheck·2018·CVSS 7.8
CVE-2018-5002 [HIGH] CWE-787 Adobe Flash Player Stack-based Buffer Overflow Vulnerability
Adobe Flash Player Stack-based Buffer Overflow Vulnerability
Adobe Flash Player have a stack-based buffer overflow vulnerability that could lead to remote code execution.
Affected: Adobe Flash Player
Required Action: The impacted product is end-of-life and should be disconnected if still in use.
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://twitter.com/craiu/status/1038046509793722368; https://unit42.paloaltonetworks.com/unit42-slicing-dicing-cve-2018-5002-payloads-new-chainshot-malware/; https://securelist.com/cve-2018-8453-used-in-targeted-attacks/88151/; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://storage.googleapis.com/gweb-uniblog-publish-prod/documents/Buy
CISA
Microsoft Win32k Privilege Escalation Vulnerability
cisa·2022-01-21·CVSS 7.8
CVE-2018-8453 [HIGH] CWE-404 Microsoft Win32k Privilege Escalation Vulnerability
Vulnerability: Microsoft Win32k Privilege Escalation Vulnerability
Affected: Microsoft Win32k
Microsoft Windows Win32k contains a vulnerability that allows an attacker to escalate privileges.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2018-8453
Remediation Due Date: 2022-07-21
Microsoft
Win32k Elevation of Privilege Vulnerability
vendor_msrc·2018-10-09·CVSS 7.0
CVE-2018-8453 [HIGH] Win32k Elevation of Privilege Vulnerability
Win32k Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system.
The update addresses this vulnerability by correcting how Win32k handles objects in memory.
Microsoft Graphics Component: Microsoft Graphics Component
Impact: Elevation of Pri
Suricata
ET MALWARE FruityArmor DNS Lookup (shelves-design .com)
suricata·2018-10-10
CVE-2018-8453 ET MALWARE FruityArmor DNS Lookup (shelves-design .com)
ET MALWARE FruityArmor DNS Lookup (shelves-design .com)
Rule: alert dns $HOME_NET any -> any any (msg:"ET MALWARE FruityArmor DNS Lookup (shelves-design .com)"; dns.query; content:"shelves-design.com"; nocase; fast_pattern; endswith; reference:url,securelist.com/cve-2018-8453-used-in-targeted-attacks/88151/; classtype:trojan-activity; sid:2026470; rev:3; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, attack_target Client_Endpoint, created_at 2018_10_10, deployment Perimeter, performance_impact Low, confidence Medium, signature_severity Major, tag FruityArmor, updated_at 2020_09_16;)
Suricata
ET MALWARE FruityArmor DNS Lookup (weekendstrips .net)
suricata·2018-10-10
CVE-2018-8453 ET MALWARE FruityArmor DNS Lookup (weekendstrips .net)
ET MALWARE FruityArmor DNS Lookup (weekendstrips .net)
Rule: alert dns $HOME_NET any -> any any (msg:"ET MALWARE FruityArmor DNS Lookup (weekendstrips .net)"; dns.query; content:"weekendstrips.net"; nocase; fast_pattern; endswith; reference:url,securelist.com/cve-2018-8453-used-in-targeted-attacks/88151/; classtype:trojan-activity; sid:2026469; rev:3; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, attack_target Client_Endpoint, created_at 2018_10_10, deployment Perimeter, performance_impact Low, confidence Medium, signature_severity Major, tag FruityArmor, updated_at 2020_09_16;)
Exploit-DB
Microsoft Windows - NtUserSetWindowFNID Win32k User Callback Privilege Escalation (Metasploit)
exploitdb·2019-07-17
CVE-2018-8453 Microsoft Windows - NtUserSetWindowFNID Win32k User Callback Privilege Escalation (Metasploit)
Microsoft Windows - NtUserSetWindowFNID Win32k User Callback Privilege Escalation (Metasploit)
---
##
# This module requires Metasploit: https://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
class MetasploitModule 'Windows NtUserSetWindowFNID Win32k User Callback',
'Description' => %q{
An elevation of privilege vulnerability exists in Windows when the Win32k component
fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability."
This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows
Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2,
Windows 10, Windows 10 Servers.
This module is tested against Windows 10 v1703 x86.
},
'License' =>
Metasploit
Windows NtUserSetWindowFNID Win32k User Callback
metasploit
Windows NtUserSetWindowFNID Win32k User Callback
Windows NtUserSetWindowFNID Win32k User Callback
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This module is tested against Windows 10 v1703 x86.
Tenable
Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect
blogs_tenable·2026-05-27
CVE-2023-4966 Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect
## Exposure Management
## Explore By Use Case
## Explore By Industry
## Tenable is the one clear leader in Exposure Management
## Exposure management
resource center
## Accelerate your exposure management strategy with practical resources and tools.
## Explore By Use Case
## Explore By Industry
## Tenable is the one clear leader in Exposure Management
## Exposure management
resource center
## Accelerate your exposure management strategy with practical resources and tools.
## Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect
Tenable Research has developed a graph-based model linking 600+ threat groups to real-world customer exposures. It reveals which vulnerabilities sit at the intersection of severity, active exploit
Securelist
APT trends report Q3 2022
blogs_securelist·2022-11-01
APT trends report Q3 2022
Table of Contents
- The most remarkable findings
- Russian-speaking activity
- Chinese-speaking activity
- Middle East
- Southeast Asia and Korean Peninsula
- Other interesting discoveries
- Final thoughts
Authors
- GReAT
For more than five years, the Global Research and Analysis Team (GReAT) at Kaspersky has been publishing quarterly summaries of advanced persistent threat (APT) activity. These summaries are based on our threat intelligence research; and they provide a representative snapshot of what we have published and discussed in greater detail in our private APT reports. They are designed to highlight the significant events and findings that we feel people should be aware of.
This is our latest installment, focusing on activities that we observed during Q3 2022.
Readers who w
Securelist
APT trends report Q3 2022
blogs_securelist·2022-11-01
APT trends report Q3 2022
Table of Contents
The most remarkable findings
Russian-speaking activity
Chinese-speaking activity
Middle East
Southeast Asia and Korean Peninsula
Other interesting discoveries
Final thoughts
Authors
GReAT
For more than five years, the Global Research and Analysis Team (GReAT) at Kaspersky has been publishing quarterly summaries of advanced persistent threat (APT) activity. These summaries are based on our threat intelligence research; and they provide a representative snapshot of what we have published and discussed in greater detail in our private APT reports. They are designed to highlight the significant events and findings that we feel people should be aware of.
This is our latest installment, focusing on activities that we observed during Q3 2022.
Readers who would like t
Qualys
Ransomware Insights from the FBI’s 2021 Internet Crime Report | Qualys
blogs_qualys·2022-05-04
Ransomware Insights from the FBI’s 2021 Internet Crime Report | Qualys
#### Table of Contents
- Top Ransomware Attack Vectors of 2021
- How Can Qualys Help?
The FBI has published its annual report on Internet crime. Qualys has analyzed its trends and statistics. In this post, we review our findings, especially with regards to the prevalence of Ransomware, and our recommendations for actions that enterprises should take to mitigate their risk.
Every year the U.S. Federal Bureau of Investigation publishes an Internet crime report which summarizes its insights on trends and threats from cybercriminals based on all cybercrimes reported to the FBI by the American public. This annual report provides fascinating insights into the threat landscape, key trends, statistics on types of crimes, the real losses resulting from them, and perhaps most importantly, key ins
Qualys
Ransomware Insights from the FBI’s 2021 Internet Crime Report
blogs_qualys·2022-05-04
Ransomware Insights from the FBI’s 2021 Internet Crime Report
## Table of Contents
Top Ransomware Attack Vectors of 2021
How Can Qualys Help?
The FBI has published its annual report on Internet crime. Qualys has analyzed its trends and statistics. In this post, we review our findings, especially with regards to the prevalence of Ransomware, and our recommendations for actions that enterprises should take to mitigate their risk.
Every year the U.S. Federal Bureau of Investigation publishes an Internet crime report which summarizes its insights on trends and threats from cybercriminals based on all cybercrimes reported to the FBI by the American public. This annual report provides fascinating insights into the threat landscape, key trends, statistics on types of crimes, the real losses resulting from them, and perhaps most importantly, key insights
Qualys
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
blogs_qualys·2022-02-23
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
#### Table of Contents
- Situation
- Directive Scope
- CISA Catalog of Known Exploited Vulnerabilities
- Detect CISA Vulnerabilities Using Qualys VMDR
- CISA Exploited RTI
- Detailed Operational Dashboard
- Remediation
- Federal Enterprises and Agencies Can Act Now
- Summary
- Getting Started
CISA released a directive in November 2021, recommending urgent and prioritized remediation of actively exploited vulnerabilities. Both government agencies and corporations should heed this advice. This blog outlines how Qualys Vulnerability Management, Detection & Response can be used by any organization to respond to this directive efficiently and effectively.
## Situation
Last November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a Binding Operational Directiv
Checkpoint
Exploit Developer Spotlight: The Story of PlayBit
blogs_checkpoint·2020-10-26·CVSS 7.8
CVE-2018-8453 [HIGH] Exploit Developer Spotlight: The Story of PlayBit
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
AI Research 2
Android Malware 23
Artificial Intelligence 4
ChatGPT 3
Check Point Research Publications 455
Cloud Security 1
CPRadio 44
Crypto 2
Data & Threat Intelligence 2
Data Analysis 0
Demos 22
Global Cyber Attack Reports 408
How To Guides 13
Ransomware 5
Russo-Ukrainian War 1
Security Report 1
Threat and data analysis 0
Threat Research 174
Web 3.0 Security 11
Wipers 0
## Exploit Developer Spotlight: The Story of PlayBit
Research By: Eyal Itkin and Itay Cohen
## Introduction
Exploits have always been an important and integral part of malicious attacks.
Checkpoint
Graphology of an Exploit – Hunting for exploits by looking for the author’s fingerprints
blogs_checkpoint·2020-10-02
CVE-2019-0859 Graphology of an Exploit – Hunting for exploits by looking for the author’s fingerprints
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
AI Research 2
Android Malware 23
Artificial Intelligence 4
ChatGPT 3
Check Point Research Publications 455
Cloud Security 1
CPRadio 44
Crypto 2
Data & Threat Intelligence 2
Data Analysis 0
Demos 22
Global Cyber Attack Reports 408
How To Guides 13
Ransomware 5
Russo-Ukrainian War 1
Security Report 1
Threat and data analysis 0
Threat Research 174
Web 3.0 Security 11
Wipers 0
## Graphology of an Exploit – Hunting for exploits by looking for the author’s fingerprints
Research by: Itay Cohen, Eyal Itkin
In the past months, our Vulnerability and Malware Research tea
Tenable
CVE-2019-11510: Critical Pulse Connect Secure Vulnerability Used in Sodinokibi Ransomware Attacks
blogs_tenable·2020-01-07·CVSS 10.0
[CRITICAL] CVE-2019-11510: Critical Pulse Connect Secure Vulnerability Used in Sodinokibi Ransomware Attacks
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Checkpoint
8th July – Threat Intelligence Bulletin
blogs_checkpoint·2019-07-08·CVSS 7.8
CVE-2018-7600 [HIGH] 8th July – Threat Intelligence Bulletin
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 8th July – Threat Intelligence Bulletin
For the latest discoveries in cyber research for the week of 8th July 2019, please download our Threat Intelligence Bulletin
TOP ATTACKS AND BREACHES
The Japanese-American international convenience store 7/11 has shut down its new mobile payment app after threat actors stole $500,000 from its users. The attackers were able to perform unwanted charges on customers’ accounts due to a flaw in the password reset function, which allows anyone to reset the password for other cu
Securelist
Sodin ransomware exploits Windows vulnerability and processor architecture
blogs_securelist·2019-07-03·CVSS 7.8
CVE-2018-8453 [HIGH] Sodin ransomware exploits Windows vulnerability and processor architecture
Authors
- Orkhan Mamedov
- Artur Pakulov
- Fedor Sinitsyn
When Sodin (also known as Sodinokibi and REvil) appeared in the first half of 2019, it immediately caught our attention for distributing itself through an Oracle Weblogic vulnerability and carrying out attacks on MSP providers. In a detailed analysis, we discovered that it also exploits the CVE-2018-8453 vulnerability to elevate privileges in Windows (rare among ransomware), and uses legitimate processor functions to circumvent security solutions.
According to our statistics, most victims were located in the Asia-Pacific region: Taiwan, Hong Kong, and South Korea.
Geographic spread of Sodin ransomware, April – June 2019
## Technical description
### Vulnerability exploitation
To escalate privileges, Trojan-Ransom.Win32.Sodin u
Securelist
Sodin ransomware exploits Windows vulnerability and processor architecture
blogs_securelist·2019-07-03·CVSS 7.8
CVE-2018-8453 [HIGH] Sodin ransomware exploits Windows vulnerability and processor architecture
Authors
Orkhan Mamedov
Artur Pakulov
Fedor Sinitsyn
When Sodin (also known as Sodinokibi and REvil) appeared in the first half of 2019, it immediately caught our attention for distributing itself through an Oracle Weblogic vulnerability and carrying out attacks on MSP providers . In a detailed analysis, we discovered that it also exploits the CVE-2018-8453 vulnerability to elevate privileges in Windows (rare among ransomware), and uses legitimate processor functions to circumvent security solutions.
According to our statistics, most victims were located in the Asia-Pacific region: Taiwan, Hong Kong, and South Korea.
Geographic spread of Sodin ransomware, April – June 2019
## Technical description
## Vulnerability exploitation
To escalate privileges, Trojan-Ransom.Win32.Sodin uses
Securelist
New win32k zero day: CVE-2019-0859
blogs_securelist·2019-04-15·CVSS 7.8
CVE-2019-0859 [HIGH] New win32k zero day: CVE-2019-0859
Authors
- Vasily Berdnikov
- Boris Larin
- Anton Ivanov
In March 2019, our automatic Exploit Prevention (EP) systems detected an attempt to exploit a vulnerability in the Microsoft Windows operating system. Further analysis of this event led to us discovering a zero-day vulnerability in win32k.sys. It was the fifth consecutive exploited Local Privilege Escalation vulnerability in Windows that we have discovered in recent months using our technologies. The previous ones were:
- Zero-day exploit (CVE-2018-8453) used in targeted attacks
- A new exploit for zero-day vulnerability CVE-2018-8589
- Zero-day in Windows Kernel Transaction Manager (CVE-2018-8611)
- The fourth horseman: CVE-2019-0797 vulnerability
On March 17, 2019 we reported our discovery to Microsoft; the company confirmed the
Securelist
New zero-day vulnerability CVE-2019-0859 in win32k.sys
blogs_securelist·2019-04-15·CVSS 7.8
[HIGH] New zero-day vulnerability CVE-2019-0859 in win32k.sys
Authors
Vasily Berdnikov
Boris Larin
Anton Ivanov
In March 2019, our automatic Exploit Prevention (EP) systems detected an attempt to exploit a vulnerability in the Microsoft Windows operating system. Further analysis of this event led to us discovering a zero-day vulnerability in win32k.sys. It was the fifth consecutive exploited Local Privilege Escalation vulnerability in Windows that we have discovered in recent months using our technologies. The previous ones were:
Zero-day exploit (CVE-2018-8453) used in targeted attacks
A new exploit for zero-day vulnerability CVE-2018-8589
Zero-day in Windows Kernel Transaction Manager (CVE-2018-8611)
The fourth horseman: CVE-2019-0797 vulnerability
On March 17, 2019 we reported our discovery to Microsoft; the company confirmed the vulnerab
Securelist
Zero-day in Windows Kernel Transaction Manager (CVE-2018-8611)
blogs_securelist·2018-12-12·CVSS 7.8
CVE-2018-8611 [HIGH] Zero-day in Windows Kernel Transaction Manager (CVE-2018-8611)
Authors
- Boris Larin
- Vladislav Stolyarov
- Anton Ivanov
## Executive summary
In October 2018, our AEP (Automatic Exploit Prevention) systems detected an attempt to exploit a vulnerability in the Microsoft Windows operating system. Further analysis led us to uncover a zero-day vulnerability in ntoskrnl.exe. We reported it to Microsoft on October 29, 2018. The company confirmed the vulnerability and assigned it CVE-2018-8611. Microsoft just released a patch, part of its December update, crediting Kaspersky Lab researchers Boris Larin (Oct0xor) and Igor Soumenkov (2igosha) with the discovery.
This is the third consecutive exploited Local Privilege Escalation vulnerability in Windows we discovered this autumn using our technologies. Unlike the previously reported vulnerabilities in win3
Securelist
Zero-day in Windows Kernel Transaction Manager (CVE-2018-8611)
blogs_securelist·2018-12-12·CVSS 7.8
CVE-2018-8611 [HIGH] Zero-day in Windows Kernel Transaction Manager (CVE-2018-8611)
Authors
Boris Larin
Vladislav Stolyarov
Anton Ivanov
## Executive summary
In October 2018, our AEP (Automatic Exploit Prevention) systems detected an attempt to exploit a vulnerability in the Microsoft Windows operating system. Further analysis led us to uncover a zero-day vulnerability in ntoskrnl.exe. We reported it to Microsoft on October 29, 2018. The company confirmed the vulnerability and assigned it CVE-2018-8611 . Microsoft just released a patch, part of its December update, crediting Kaspersky Lab researchers Boris Larin ( Oct0xor ) and Igor Soumenkov ( 2igosha ) with the discovery.
This is the third consecutive exploited Local Privilege Escalation vulnerability in Windows we discovered this autumn using our technologies. Unlike the previously reported vulnerabilities in win
Securelist
Kaspersky Security Bulletin 2018. Top security stories
blogs_securelist·2018-12-03
Kaspersky Security Bulletin 2018. Top security stories
Table of Contents
- Introduction
- Targeted attack campaigns
- Mobile APT campaigns
- Exploits
- Browser extensions – extending the reach of cybercriminals
- The World Cup of fraud
- Financial fraud on an industrial scale
- Ransomware – still a threat
- Asacub and banking Trojans
- Smart doesn’t mean secure
- Our data in their hands
Authors
- David Emm
- Victor Chebyshev
- Kaspersky Security Bulletin 2018. Statistics
- Kaspersky Security Bulletin 2018. Story of the year: miners
- Kaspersky Security Bulletin 2018. Threat Predictions for 2019
## Introduction
The internet is now woven into the fabric of our lives. Many people routinely bank, shop and socialize online and the internet is the lifeblood of commercial organizations. The dependence on technology of governments, businesses a
Securelist
Kaspersky Security Bulletin 2018. Top security stories
blogs_securelist·2018-12-03
Kaspersky Security Bulletin 2018. Top security stories
Table of Contents
Introduction
Targeted attack campaigns
Mobile APT campaigns
Exploits
Browser extensions – extending the reach of cybercriminals
The World Cup of fraud
Financial fraud on an industrial scale
Ransomware – still a threat
Asacub and banking Trojans
Smart doesn’t mean secure
Our data in their hands
Authors
David Emm
Victor Chebyshev
Kaspersky Security Bulletin 2018. Statistics
Kaspersky Security Bulletin 2018. Story of the year: miners
Kaspersky Security Bulletin 2018. Threat Predictions for 2019
## Introduction
The internet is now woven into the fabric of our lives. Many people routinely bank, shop and socialize online and the internet is the lifeblood of commercial organizations. The dependence on technology of governments, businesses and consumers provide
Trendmicro
Patch Tuesday Fixes Zero-Day Win32k Bug
blogs_trendmicro·2018-11-14·CVSS 7.8
CVE-2018-8589 [HIGH] Patch Tuesday Fixes Zero-Day Win32k Bug
Exploits & Vulnerabilities
# Patch Tuesday Fixes Zero-Day Win32k Bug
This month’s round of updates, which fixes 63 bugs, includes a patch for a zero-day vulnerability (CVE-2018-8589) that is already being used in malicious attacks.
By: Trend Micro
2018/11/14
Read time: ( words)
Save to Folio
As the year comes to a close, updates for both Microsoft and Adobe products and services are still ongoing via Patch Tuesday. This month’s round of updates, which fixes 63 bugs, includes a patch for a zero-day vulnerability that is already being used in malicious attacks. Perhaps the most notable vulnerability addressed this month is CVE-2018-8589, another Win32k Elevation of Privilege Vulnerability that is similar to October’s CVE-2018-8453, which allows an attacker to make use of specially craf
Trendmicro
Patch Tuesday Fixes Zero-Day Win32k Bug
blogs_trendmicro·2018-11-14·CVSS 7.8
CVE-2018-8589 [HIGH] Patch Tuesday Fixes Zero-Day Win32k Bug
Exploits y vulnerabilidades
## Patch Tuesday Fixes Zero-Day Win32k Bug
This month’s round of updates, which fixes 63 bugs, includes a patch for a zero-day vulnerability (CVE-2018-8589) that is already being used in malicious attacks.
By: Trend Micro Nov 14, 2018 Read time: ( words)
Save to Folio
As the year comes to a close, updates for both Microsoft and Adobe products and services are still ongoing via Patch Tuesday . This month’s round of updates, which fixes 63 bugs, includes a patch for a zero-day vulnerability that is already being used in malicious attacks. Perhaps the most notable vulnerability addressed this month is CVE-2018-8589 , another Win32k Elevation of Privilege Vulnerability that is similar to October ’s CVE-2018-8453 , which allows an attacker to make use of special
Trendmicro
Patch Tuesday Fixes Zero-Day Win32k Bug
blogs_trendmicro·2018-11-14·CVSS 7.8
CVE-2018-8589 [HIGH] Patch Tuesday Fixes Zero-Day Win32k Bug
Ausnutzung von Schwachstellen
## Patch Tuesday Fixes Zero-Day Win32k Bug
This month’s round of updates, which fixes 63 bugs, includes a patch for a zero-day vulnerability (CVE-2018-8589) that is already being used in malicious attacks.
By: Trend Micro Nov 14, 2018 Read time: ( words)
Save to Folio
As the year comes to a close, updates for both Microsoft and Adobe products and services are still ongoing via Patch Tuesday . This month’s round of updates, which fixes 63 bugs, includes a patch for a zero-day vulnerability that is already being used in malicious attacks. Perhaps the most notable vulnerability addressed this month is CVE-2018-8589 , another Win32k Elevation of Privilege Vulnerability that is similar to October ’s CVE-2018-8453 , which allows an attacker to make use of speci
Trendmicro
Patch Tuesday Fixes Zero-Day Win32k Bug
blogs_trendmicro·2018-11-14·CVSS 7.8
CVE-2018-8589 [HIGH] Patch Tuesday Fixes Zero-Day Win32k Bug
Sfruttamento vulnerabilità
## Patch Tuesday Fixes Zero-Day Win32k Bug
This month’s round of updates, which fixes 63 bugs, includes a patch for a zero-day vulnerability (CVE-2018-8589) that is already being used in malicious attacks.
By: Trend Micro Nov 14, 2018 Read time: ( words)
Save to Folio
As the year comes to a close, updates for both Microsoft and Adobe products and services are still ongoing via Patch Tuesday . This month’s round of updates, which fixes 63 bugs, includes a patch for a zero-day vulnerability that is already being used in malicious attacks. Perhaps the most notable vulnerability addressed this month is CVE-2018-8589 , another Win32k Elevation of Privilege Vulnerability that is similar to October ’s CVE-2018-8453 , which allows an attacker to make use of speciall
Trendmicro
Patch Tuesday Fixes Zero-Day Win32k Bug
blogs_trendmicro·2018-11-14·CVSS 7.8
CVE-2018-8589 [HIGH] Patch Tuesday Fixes Zero-Day Win32k Bug
Exploits & Vulnerabilities
## Patch Tuesday Fixes Zero-Day Win32k Bug
This month’s round of updates, which fixes 63 bugs, includes a patch for a zero-day vulnerability (CVE-2018-8589) that is already being used in malicious attacks.
By: Trend Micro Nov 14, 2018 Read time: ( words)
Save to Folio
As the year comes to a close, updates for both Microsoft and Adobe products and services are still ongoing via Patch Tuesday . This month’s round of updates, which fixes 63 bugs, includes a patch for a zero-day vulnerability that is already being used in malicious attacks. Perhaps the most notable vulnerability addressed this month is CVE-2018-8589 , another Win32k Elevation of Privilege Vulnerability that is similar to October ’s CVE-2018-8453 , which allows an attacker to make use of speciall
Trendmicro
Patch Tuesday Fixes Zero-Day Win32k Bug
blogs_trendmicro·2018-11-14·CVSS 7.8
CVE-2018-8589 [HIGH] Patch Tuesday Fixes Zero-Day Win32k Bug
Exploits & Vulnerabilities
## Patch Tuesday Fixes Zero-Day Win32k Bug
This month’s round of updates, which fixes 63 bugs, includes a patch for a zero-day vulnerability (CVE-2018-8589) that is already being used in malicious attacks.
By: Trend Micro 2018/11/14 Read time: ( words)
Save to Folio
As the year comes to a close, updates for both Microsoft and Adobe products and services are still ongoing via Patch Tuesday . This month’s round of updates, which fixes 63 bugs, includes a patch for a zero-day vulnerability that is already being used in malicious attacks. Perhaps the most notable vulnerability addressed this month is CVE-2018-8589 , another Win32k Elevation of Privilege Vulnerability that is similar to October ’s CVE-2018-8453 , which allows an attacker to make use of specially
Tenable
Microsoft’s October 2018 Security Update: There's More to the Story
blogs_tenable·2018-10-15
Microsoft’s October 2018 Security Update: There's More to the Story
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Microsoft’s October 2018 Security Update: There's More to the Story
blogs_tenable·2018-10-15·CVSS 7.8
[HIGH] Microsoft’s October 2018 Security Update: There's More to the Story
Blog / Cyber Exposure Alerts
Subscribe
# Microsoft’s October 2018 Security Update: There's More to the Story
Satnam Narang
October 15, 2018
3 Min Read
A week after Microsoft addressed 49 vulnerabilities in its October 2018 Security Update, new developments have emerged that change the threat profile of some of them.
## Background
On Tuesday, October 9, Microsoft released its October 2018 Security Update, also known as Patch Tuesday. This security update contained fixes for 49 vulnerabilities. Since the publication of this security update, new developments have emerged that change the threat profile of some of these vulnerabilities. The most notable developments center around vulnerabilities in Microsoft Windows Shell, Microsoft Win32k.sys and Microsoft JET Database Engine.
## Vulne
Krebs
Patch Tuesday, October 2018 Edition
blogs_krebs·2018-10-11·CVSS 7.8
CVE-2018-8453 [HIGH] Patch Tuesday, October 2018 Edition
Microsoft this week released software updates to fix roughly 50 security problems with various versions of its Windows operating system and related software, including one flaw that is already being exploited and another for which exploit code is publicly available.
The zero-day bug — CVE-2018-8453 — affects Windows versions 7, 8.1, 10 and Server 2008, 2012, 2016 and 2019. According to security firm Ivanti , an attacker first needs to log into the operating system, but then can exploit this vulnerability to gain administrator privileges.
Another vulnerability patched on Tuesday — CVE-2018-8423 — was publicly disclosed last month along with sample exploit code. This flaw involves a component shipped on all Windows machines and used by a number of programs, and could be exploited by gettin
Securelist
Zero-day exploit (CVE-2018-8453) used in targeted attacks | Securelist
blogs_securelist·2018-10-10·CVSS 7.8
CVE-2018-8453 [HIGH] Zero-day exploit (CVE-2018-8453) used in targeted attacks | Securelist
Authors
- AMR
Yesterday, Microsoft published their security bulletin, which patches CVE-2018-8453, among others. It is a vulnerability in win32k.sys discovered by Kaspersky Lab in August. We reported this vulnerability to Microsoft on August 17, 2018. Microsoft confirmed the vulnerability and designated it CVE-2018-8453.
In August 2018 our Automatic Exploit Prevention (AEP) systems detected an attempt to exploit a vulnerability in Microsoft Windows operating system. Further analysis into this case led us to uncover a zero-day vulnerability in win32k.sys. The exploit was executed by the first stage of a malware installer to get necessary privileges for persistence on the victim’s system. The code of the exploit is of high quality and written with the aim of reliably exploiting as many di
Trendmicro
Patch Tuesday Fixes JET Database Engine, Win32K bugs
blogs_trendmicro·2018-10-10·CVSS 7.8
CVE-2018-8423 [HIGH] Patch Tuesday Fixes JET Database Engine, Win32K bugs
Exploits y vulnerabilidades
## Patch Tuesday Fixes JET Database Engine, Win32K bugs
This month’s Patch Tuesday fixes a JET Database Engine Vulnerability (CVE-2018-8423) that Trend Micro’s Zero Day Initiative (ZDI) disclosed last September together with a proof of concept code.
By: Trend Micro Oct 10, 2018 Read time: ( words)
Save to Folio
This month’s Patch Tuesday fixes a JET Database Engine Vulnerability ( CVE-2018-8423 ) that Trend Micro’s Zero Day Initiative (ZDI) disclosed last September together with a proof of concept code. The vulnerability, which was rated as Important, can allow an attacker to send a specially crafted file containing data in the JET database format. When accessed on a machine, it can allow the JET database engine to execute an out-of-bounds write that would
Securelist
Zero-day exploit (CVE-2018-8453) used in targeted attacks
blogs_securelist·2018-10-10·CVSS 7.8
CVE-2018-8453 [HIGH] Zero-day exploit (CVE-2018-8453) used in targeted attacks
Authors
AMR
Yesterday, Microsoft published their security bulletin, which patches CVE-2018-8453 , among others. It is a vulnerability in win32k.sys discovered by Kaspersky Lab in August. We reported this vulnerability to Microsoft on August 17, 2018. Microsoft confirmed the vulnerability and designated it CVE-2018-8453.
In August 2018 our Automatic Exploit Prevention (AEP) systems detected an attempt to exploit a vulnerability in Microsoft Windows operating system. Further analysis into this case led us to uncover a zero-day vulnerability in win32k.sys. The exploit was executed by the first stage of a malware installer to get necessary privileges for persistence on the victim’s system. The code of the exploit is of high quality and written with the aim of reliably exploiting as many dif
Trendmicro
Patch Tuesday Fixes JET Database Engine, Win32K bugs
blogs_trendmicro·2018-10-10·CVSS 7.8
CVE-2018-8423 [HIGH] Patch Tuesday Fixes JET Database Engine, Win32K bugs
Exploits & Vulnerabilities
# Patch Tuesday Fixes JET Database Engine, Win32K bugs
This month’s Patch Tuesday fixes a JET Database Engine Vulnerability (CVE-2018-8423) that Trend Micro’s Zero Day Initiative (ZDI) disclosed last September together with a proof of concept code.
By: Trend Micro
2018/10/10
Read time: ( words)
Save to Folio
This month’s Patch Tuesday fixes a JET Database Engine Vulnerability (CVE-2018-8423) that Trend Micro’s Zero Day Initiative (ZDI) disclosed last September together with a proof of concept code. The vulnerability, which was rated as Important, can allow an attacker to send a specially crafted file containing data in the JET database format. When accessed on a machine, it can allow the JET database engine to execute an out-of-bounds write that would then
Trendmicro
Patch Tuesday Fixes JET Database Engine, Win32K bugs
blogs_trendmicro·2018-10-10·CVSS 7.8
CVE-2018-8423 [HIGH] Patch Tuesday Fixes JET Database Engine, Win32K bugs
Exploits & Vulnerabilities
## Patch Tuesday Fixes JET Database Engine, Win32K bugs
This month’s Patch Tuesday fixes a JET Database Engine Vulnerability (CVE-2018-8423) that Trend Micro’s Zero Day Initiative (ZDI) disclosed last September together with a proof of concept code.
By: Trend Micro Oct 10, 2018 Read time: ( words)
Save to Folio
This month’s Patch Tuesday fixes a JET Database Engine Vulnerability ( CVE-2018-8423 ) that Trend Micro’s Zero Day Initiative (ZDI) disclosed last September together with a proof of concept code. The vulnerability, which was rated as Important, can allow an attacker to send a specially crafted file containing data in the JET database format. When accessed on a machine, it can allow the JET database engine to execute an out-of-bounds write that would t
Trendmicro
Patch Tuesday Fixes JET Database Engine, Win32K bugs
blogs_trendmicro·2018-10-10·CVSS 7.8
CVE-2018-8423 [HIGH] Patch Tuesday Fixes JET Database Engine, Win32K bugs
Exploits & Vulnerabilities
## Patch Tuesday Fixes JET Database Engine, Win32K bugs
This month’s Patch Tuesday fixes a JET Database Engine Vulnerability (CVE-2018-8423) that Trend Micro’s Zero Day Initiative (ZDI) disclosed last September together with a proof of concept code.
By: Trend Micro 2018/10/10 Read time: ( words)
Save to Folio
This month’s Patch Tuesday fixes a JET Database Engine Vulnerability ( CVE-2018-8423 ) that Trend Micro’s Zero Day Initiative (ZDI) disclosed last September together with a proof of concept code. The vulnerability, which was rated as Important, can allow an attacker to send a specially crafted file containing data in the JET database format. When accessed on a machine, it can allow the JET database engine to execute an out-of-bounds write that would the
Trendmicro
Patch Tuesday Fixes JET Database Engine, Win32K bugs
blogs_trendmicro·2018-10-10·CVSS 7.8
CVE-2018-8423 [HIGH] Patch Tuesday Fixes JET Database Engine, Win32K bugs
Ausnutzung von Schwachstellen
## Patch Tuesday Fixes JET Database Engine, Win32K bugs
This month’s Patch Tuesday fixes a JET Database Engine Vulnerability (CVE-2018-8423) that Trend Micro’s Zero Day Initiative (ZDI) disclosed last September together with a proof of concept code.
By: Trend Micro Oct 10, 2018 Read time: ( words)
Save to Folio
This month’s Patch Tuesday fixes a JET Database Engine Vulnerability ( CVE-2018-8423 ) that Trend Micro’s Zero Day Initiative (ZDI) disclosed last September together with a proof of concept code. The vulnerability, which was rated as Important, can allow an attacker to send a specially crafted file containing data in the JET database format. When accessed on a machine, it can allow the JET database engine to execute an out-of-bounds write that woul
Talos
Microsoft Patch Tuesday — October 18: Vulnerability disclosures and Snort coverage
blogs_talos·2018-10-09·CVSS 7.5
[HIGH] Microsoft Patch Tuesday — October 18: Vulnerability disclosures and Snort coverage
Microsoft released its monthly security update today, disclosing a variety of vulnerabilities in several of its products. The latest Patch Tuesday covers 49 vulnerabilities, 12 of which are rated "critical," 34 that are rated "important,” two that are considered to have “moderate” severity and one that’s rated as “low.”
The advisories cover bugs in the Chakra scripting engine, the Microsoft Edge internet browser and the Microsoft Office suite of products, among other software.
This update also includes a critical advisory that covers updates to the Microsoft Office suite of products.
Please visit the SNORTⓇ blog here if you would like to know more about the coverage we have for these vulnerabilities.
Critical vulnerabilities
Microsoft has disclosed 12 critical vulnerabilities this mont
Talos
Microsoft Patch Tuesday — October 18: Vulnerability disclosures and Snort coverage
blogs_talos·2018-10-09·CVSS 7.5
[HIGH] Microsoft Patch Tuesday — October 18: Vulnerability disclosures and Snort coverage
## Microsoft Patch Tuesday — October 18: Vulnerability disclosures and Snort coverage
Microsoft released its monthly security update today, disclosing a variety of vulnerabilities in several of its products. The latest Patch Tuesday covers 49 vulnerabilities, 12 of which are rated "critical," 34 that are rated "important,” two that are considered to have “moderate” severity and one that’s rated as “low.”
The advisories cover bugs in the Chakra scripting engine, the Microsoft Edge internet browser and the Microsoft Office suite of products, among other software.
This update also includes a critical advisory that covers updates to the Microsoft Office suite of products .
Please visit the SNORTⓇ blog here if you would like to know more about the coverage we have for these vulnerabilities.
Zscaler
Security Advisory – October 09, 2018
blogs_zscaler·CVSS 9.3
[CRITICAL] Security Advisory – October 09, 2018
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
arXiv
Towards Cyber Security for Low-Carbon Transportation: Overview, Challenges and Future Directions
arxiv_fulltext·2023-05-24
Towards Cyber Security for Low-Carbon Transportation: Overview, Challenges and Future Directions
[mode = title]Towards Cyber Security for Low-Carbon Transportation: Overview, Challenges and Future Directions
[1]Corresponding author
[1]Yue Cao[type=editor, auid=000, bioid=1]
[1]Sifan Li
[1]Chenchen Lv
[1]Di Wang[orcid=0000-0003-0104-3136]
[1]
[email protected]
[2]Hongjian Sun
[3]Jing Jiang
[4]Fanlin Meng
[5]Lexi Xu
[5]Xinzhou Cheng
[1]School of Cyber Science and Engineering, Wuhan University, Wuhan 430072, China
[2]Department of Engineering, Durham University, Durham, DH1 3LE, UK
[3]Department of Mathematics, Physics and Electrical Engineering, Northumbria University, Newcastle, NE1 8ST, UK
[4]Alliance Manchester Business School, The University of Manchester, Manchester, M15 6PB, UK
[5]China Unicom Research Institute, Beijing, 100048, China
## Abstract
[S U M M A R Y
http://packetstormsecurity.com/files/153669/Microsoft-Windows-NtUserSetWindowFNID-Win32k-User-Callback.htmlhttp://www.securityfocus.com/bid/105467http://www.securitytracker.com/id/1041828https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8453https://securelist.com/cve-2018-8453-used-in-targeted-attackhttp://packetstormsecurity.com/files/153669/Microsoft-Windows-NtUserSetWindowFNID-Win32k-User-Callback.htmlhttp://www.securityfocus.com/bid/105467http://www.securitytracker.com/id/1041828https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8453https://securelist.com/cve-2018-8453-used-in-targeted-attackhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-8453
2018-10-10
Published
2022-01-21
Added to CISA KEV
Exploited in the wild