CVE-2018-8453
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- March 14, 2018
- Published Date
- October 10, 2018
- Last Updated
- February 07, 2025
- Vendor
- Microsoft
- Product
- Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers
- Description
- An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
CVSS Scores
SSVC Information
- Exploitation
- active
- Technical Impact
- total
References
http://www.securitytracker.com/id/1041828
https://securelist.com/cve-2018-8453-used-in-targeted-attack
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8453
http://www.securityfocus.com/bid/105467
http://packetstormsecurity.com/files/153669/Microsoft-Windows-NtUserSetWindowFNID-Win32k-User-Callback.html
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2022-01-21 00:00:00 UTC |
Scanner Integrations
Scanner | URL | Date Detected |
---|---|---|
Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/local/cve_2018_8453_win32k_priv_esc.rb | 2025-04-29 11:01:40 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
cve_2018_8453_win32k_priv_esc
Type: metasploit • Created: Unknown
Metasploit module for CVE-2018-8453
thepwnrip/leHACK-Analysis-of-CVE-2018-8453
Type: github • Created: 2019-07-08 13:06:10 UTC • Stars: 13