ZeroHour

CVE-2018-8453

KEV ransomware PoC ×2mass

Win32k Elevation of Privilege Flaw in Windows 7-10 and Windows Server (CVE-2018-8453)

CISA: Microsoft Win32k Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
70%p99
Published
()
KEV added
AI analysis

CVE-2018-8453 is an elevation of privilege vulnerability in the Windows Win32k kernel component, which fails to properly handle objects in memory, including the Win32k user-callback path reachable via NtUserSetWindowFNID. An attacker who can already execute code on an affected machine can trigger the flaw to escalate privileges, gaining the equivalent of SYSTEM-level rights with high impact on confidentiality, integrity, and availability. All broadly deployed Windows releases of the era are affected, spanning Windows 7, 8.1, RT 8.1, Windows 10 (1507 through 1809), and Windows Server 2008 through 2019, so any unpatched Windows desktop or server is in scope. The flaw was exploited as a zero-day by the FruityArmor APT in targeted attacks in the Middle East, disclosed and patched in Microsoft's October 2018 Patch Tuesday, and has public proof-of-concept code. It is confirmed exploited in the wild: it sits in CISA's Known Exploited Vulnerabilities catalog (added 2022-01-21) with known ransomware use, and EPSS assigns a 70% probability of exploitation within 30 days.

What to do: Apply Microsoft's October 2018 (or later) cumulative security updates to all affected Windows 7/8.1/RT 8.1/Windows 10 clients and Windows Server 2008-2019 systems, per the vendor instructions required by CISA's KEV catalog. Prioritize multi-user hosts such as terminal/RDS servers and workstations where users can run untrusted code, since the attack requires local code execution with user interaction. Systems still on Windows 7/8.1 or Server 2008/2008 R2/2012 should be moved to Extended Security Updates or upgraded, and defenders should hunt for signs of FruityArmor-style activity on long-lived unpatched hosts.

Affected
microsoft Windows 101507, 1607, 1703, 1709, 1803, 1809
microsoft Windows 7all supported releases as listed by Microsoft
microsoft Windows 8.1all supported releases as listed by Microsoft
microsoft Windows RT 8.1all supported releases as listed by Microsoft
microsoft Windows Server 20082008 and 2008 R2
microsoft Windows Server 20122012 and 2012 R2
microsoft Windows Server 2016all supported releases as listed by Microsoft
microsoft Windows Server 2019all supported releases as listed by Microsoft
microsoft Windows Server (Semi-Annual Channel)1709, 1803
Estimated exposure
masshundreds of millions to ~1 billion+ Windows installations (Windows 10 alone ran on roughly 700 million active devices in 2018) — The flaw spans essentially every Windows client and server edition in production at the time, and public figures placed Windows 10 alone near 700 million active devices in 2018, so the affected installed base is on the order of hundreds of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

CISA Known Exploited Vulnerability
Affected
Microsoft Win32k
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1703, windows 10 1709, windows 10 1803, windows 10 1809, windows 7, windows 8.1, windows rt 8.1, windows server 1709, windows server 1803, windows server 2008
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news