ZeroHour

CVE-2018-8440

KEV ransomware PoC mass

Local Privilege Escalation in Windows ALPC Handling (Win 7–10, Server 2008–2016)

CISA: Microsoft Windows Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
18%p97
Published
()
KEV added
AI analysis

An elevation-of-privilege vulnerability exists in the way Windows handles calls to the Advanced Local Procedure Call (ALPC) facility, rated 7.8 High with a local attack vector and only low privileges required. An attacker who can already run code on a machine as a low-privileged user can send crafted ALPC messages that the OS mishandles, elevating their privileges to SYSTEM/administrator without any user interaction. Successful exploitation yields full local control (high impact on confidentiality, integrity and availability) and is typically used to consolidate a foothold or escape low-privilege contexts, including in ransomware chains. Affected systems are Windows 7, 8.1, RT 8.1, Windows 10 (1607, 1703, 1709, 1803), Windows 10 Servers, and Windows Server 2008 through 2016 — essentially every Windows client and server platform in support at disclosure. The flaw was publicly demonstrated via a published proof of concept in August 2018, fixed in Microsoft's September 2018 security updates, and is actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-28 with known ransomware use, and EPSS puts 30-day exploitation probability at 18.4% (97th percentile).

What to do: Apply the September 2018 (or later) Microsoft cumulative/monthly rollup updates across all affected Windows client and server systems, prioritizing servers and domain-joined hosts given known ransomware use and the CISA KEV listing. Legacy machines that no longer receive updates (e.g., Windows 7, Server 2008/2008 R2, 2012/2012 R2) should be upgraded to a supported OS or covered by Extended Security Updates. Verify remediation by confirming the September 2018 patch level is present on each host, since OS version alone does not indicate exposure.

Affected
Microsoft Windows 101607, 1703, 1709, 1803 (CPE-listed; CISA description lists Windows 10 broadly)
Microsoft Windows 10 Serversall editions per CISA listing (server editions of Windows 10)
Microsoft Windows 7all supported editions (no service pack pinned in source data)
Microsoft Windows 8.1all supported editions (no service pack pinned in source data)
Microsoft Windows RT 8.1all supported editions (no service pack pinned in source data)
Microsoft Windows Server 2008all supported editions, including 2008 R2 (per CISA description)
Microsoft Windows Server 2012all supported editions, including 2012 R2 (per CISA description)
Microsoft Windows Server 2016all supported editions (no version detail beyond family in source data)
Estimated exposure
mass≈1 billion+ Windows installations were in affected versions at the 2018 disclosure; the residual unpatched estate today is likely in the millions of legacy… — The affected families (Windows 7/8.1/10 clients and Server 2008–2016) made up the overwhelming majority of the roughly 1.4-billion-strong Windows install base in 2018, so virtually every Windows system unpatched before the September 2018…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC), aka "Windows ALPC Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoft
Products
windows 10 1607, windows 10 1703, windows 10 1709, windows 10 1803, windows 7, windows 8.1, windows rt 8.1, windows server 2008, windows server 2012, windows server 2016
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news