7.8
CVE-2018-8589
- EPSS 3.02%
- Veröffentlicht 14.11.2018 01:29:02
- Zuletzt bearbeitet 28.10.2025 13:48:34
- Erkennungen
An elevation of privilege vulnerability exists when Windows improperly handles calls to Win32k.sys, aka "Windows Win32k Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows Server 2008 Version - Update sp2
Microsoft ≫ Windows Server 2008 Version r2 Update sp1 HwPlatform itanium
Microsoft ≫ Windows Server 2008 Version r2 Update sp1 HwPlatform x64
23.05.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog
Microsoft Win32k Privilege Escalation Vulnerability
SchwachstelleA privilege escalation vulnerability exists when Windows improperly handles calls to Win32k.sys. An attacker who successfully exploited this vulnerability could run remote code in the security context of the local system.
BeschreibungApply updates per vendor instructions.
Erforderliche Maßnahmen| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.02% | 0.858 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
| CISA-ADP | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
http://www.securityfocus.com/bid/105796
http://www.securitytracker.com/id/1042140
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8589
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-8589