7.8
CVE-2018-8611
- EPSS 6.41%
- Veröffentlicht 12.12.2018 00:29:00
- Zuletzt bearbeitet 08.04.2025 15:44:59
- Quelle secure@microsoft.com
- Teams Watchlist Login
- Unerledigt Login
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "Windows Kernel Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 10 1607 Version-
Microsoft ≫ Windows 10 1703 Version-
Microsoft ≫ Windows 10 1709 Version-
Microsoft ≫ Windows 10 1803 Version-
Microsoft ≫ Windows 10 1809 Version-
Microsoft ≫ Windows 8.1 Version- SwEditionpro_n
Microsoft ≫ Windows Rt 8.1 Version-
Microsoft ≫ Windows Server 2008 Version- Updatesp2
Microsoft ≫ Windows Server 2008 Versionr2 HwPlatformitanium
Microsoft ≫ Windows Server 2008 Versionr2 HwPlatformx64
Microsoft ≫ Windows Server 2012 Version-
Microsoft ≫ Windows Server 2012 Versionr2
Microsoft ≫ Windows Server 2016 Version-
Microsoft ≫ Windows Server 2019 Version-
24.05.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog
Microsoft Windows Kernel Privilege Escalation Vulnerability
SchwachstelleA privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory.
BeschreibungApply updates per vendor instructions.
Erforderliche MaßnahmenTyp | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 6.41% | 0.907 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-404 Improper Resource Shutdown or Release
The product does not release or incorrectly releases a resource before it is made available for re-use.