cve-2018-8589
HIGH CVSS 7.8 cisa_known_exploited
Description
A privilege escalation vulnerability exists when Windows improperly handles calls to Win32k.sys. An attacker who successfully exploited this vulnerability could run remote code in the security context of the local system.
Timeline
- Published
- 2022-05-23
- Last Modified
- 2022-05-23
CVSS Details
CVSS details not available.
Affected Products
No product information available.
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"cvss": 7.8,
"datePublished": "2022-05-23",
"dateUpdated": "2022-05-23",
"description": "A privilege escalation vulnerability exists when Windows improperly handles calls to Win32k.sys. An attacker who successfully exploited this vulnerability could run remote code in the security context of the local system.",
"dueDate": "2022-06-13",
"id": "CVE-2018-8589",
"kev_catalogs": [
"cisa"
],
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://nvd.nist.gov/vuln/detail/CVE-2018-8589",
"product": "Win32k",
"requiredAction": "Apply updates per vendor instructions.",
"severity": "HIGH",
"source": "cisa_known_exploited",
"title": "Microsoft Win32k Privilege Escalation Vulnerability",
"vendor": "Microsoft"
}
Enrichment data
Aggregated bundle (all enrichments)