7.8

CVE-2018-8611

Warning

An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "Windows Kernel Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

Data is provided by the National Vulnerability Database (NVD)
MicrosoftWindows 10 1607 Version-
MicrosoftWindows 10 1703 Version-
MicrosoftWindows 10 1709 Version-
MicrosoftWindows 10 1803 Version-
MicrosoftWindows 10 1809 Version-
MicrosoftWindows 7 Version- Updatesp1
MicrosoftWindows 8.1 Version- SwEditionpro_n
MicrosoftWindows Rt 8.1 Version-
MicrosoftWindows Server 2008 Version- Updatesp2
MicrosoftWindows Server 2008 Versionr2 HwPlatformitanium
MicrosoftWindows Server 2008 Versionr2 HwPlatformx64

24.05.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

Microsoft Windows Kernel Privilege Escalation Vulnerability

Vulnerability

A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory.

Description

Apply updates per vendor instructions.

Required actions
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 6.41% 0.907
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
134c704f-9b21-4f2e-91b3-4a467353bcc0 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-404 Improper Resource Shutdown or Release

The product does not release or incorrectly releases a resource before it is made available for re-use.