CVE-2018-8440
KEV ransomware PoC massLocal Privilege Escalation in Windows ALPC Handling (Win 7–10, Server 2008–2016)
CISA: Microsoft Windows Privilege Escalation Vulnerability
An elevation-of-privilege vulnerability exists in the way Windows handles calls to the Advanced Local Procedure Call (ALPC) facility, rated 7.8 High with a local attack vector and only low privileges required. An attacker who can already run code on a machine as a low-privileged user can send crafted ALPC messages that the OS mishandles, elevating their privileges to SYSTEM/administrator without any user interaction. Successful exploitation yields full local control (high impact on confidentiality, integrity and availability) and is typically used to consolidate a foothold or escape low-privilege contexts, including in ransomware chains. Affected systems are Windows 7, 8.1, RT 8.1, Windows 10 (1607, 1703, 1709, 1803), Windows 10 Servers, and Windows Server 2008 through 2016 — essentially every Windows client and server platform in support at disclosure. The flaw was publicly demonstrated via a published proof of concept in August 2018, fixed in Microsoft's September 2018 security updates, and is actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-28 with known ransomware use, and EPSS puts 30-day exploitation probability at 18.4% (97th percentile).
What to do: Apply the September 2018 (or later) Microsoft cumulative/monthly rollup updates across all affected Windows client and server systems, prioritizing servers and domain-joined hosts given known ransomware use and the CISA KEV listing. Legacy machines that no longer receive updates (e.g., Windows 7, Server 2008/2008 R2, 2012/2012 R2) should be upgraded to a supported OS or covered by Extended Security Updates. Verify remediation by confirming the September 2018 patch level is present on each host, since OS version alone does not indicate exposure.
| Microsoft Windows 10 | 1607, 1703, 1709, 1803 (CPE-listed; CISA description lists Windows 10 broadly) |
| Microsoft Windows 10 Servers | all editions per CISA listing (server editions of Windows 10) |
| Microsoft Windows 7 | all supported editions (no service pack pinned in source data) |
| Microsoft Windows 8.1 | all supported editions (no service pack pinned in source data) |
| Microsoft Windows RT 8.1 | all supported editions (no service pack pinned in source data) |
| Microsoft Windows Server 2008 | all supported editions, including 2008 R2 (per CISA description) |
| Microsoft Windows Server 2012 | all supported editions, including 2012 R2 (per CISA description) |
| Microsoft Windows Server 2016 | all supported editions (no version detail beyond family in source data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC), aka "Windows ALPC Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1703, windows 10 1709, windows 10 1803, windows 7, windows 8.1, windows rt 8.1, windows server 2008, windows server 2012, windows server 2016
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H