cbcvebase.
CVE-2018-8639
published 2018-12-12

CVE-2018-8639: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of…

PriorityP186high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2025-03-24
Exploited in the wild
EPSS
22.35%
97.4th percentile
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8641.

Affected

60 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10_servers
microsoftwindows_10_servers
microsoftwindows_7
microsoftwindows_7
microsoftwindows_8.1

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2018-8639 requires local, authenticated access — detection should focus on suspicious local privilege escalation attempts via Win32k kernel-mode driver, specifically processes spawning with elevated kernel-mode privileges after running a crafted application
  • Monitor for post-exploitation indicators: new account creation with full user rights, unexpected program installations, or unauthorized data modification following local logon events — these are the attacker's follow-on actions after successful exploitation
  • The vulnerability is in the Win32k component (win32k.sys); monitor for anomalous kernel-mode code execution originating from user-mode processes interacting with Win32k objects
  • ·Microsoft's own advisory at time of publication listed exploit status as 'Publicly Disclosed: No; Exploited: No' — however CISA's KEV catalog subsequently confirmed active exploitation, meaning the MSRC advisory status is outdated and should not be relied upon for risk prioritization
  • ·CVE-2018-8639 is distinct from CVE-2018-8641, which is a separate Win32k EoP vulnerability patched in the same December 2018 cycle — do not conflate the two when scoping patch verification
  • ·Exploitation requires the attacker to already be locally authenticated on the target system — this is not a remote code execution vector; network-perimeter controls alone are insufficient mitigation

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vulncheck7.8HIGH
cisa7.8HIGH
vendor_msrc7.0HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.