CVE-2018-8453
KEV ransomware PoC ×2massWin32k Elevation of Privilege Flaw in Windows 7-10 and Windows Server (CVE-2018-8453)
CISA: Microsoft Win32k Privilege Escalation Vulnerability
CVE-2018-8453 is an elevation of privilege vulnerability in the Windows Win32k kernel component, which fails to properly handle objects in memory, including the Win32k user-callback path reachable via NtUserSetWindowFNID. An attacker who can already execute code on an affected machine can trigger the flaw to escalate privileges, gaining the equivalent of SYSTEM-level rights with high impact on confidentiality, integrity, and availability. All broadly deployed Windows releases of the era are affected, spanning Windows 7, 8.1, RT 8.1, Windows 10 (1507 through 1809), and Windows Server 2008 through 2019, so any unpatched Windows desktop or server is in scope. The flaw was exploited as a zero-day by the FruityArmor APT in targeted attacks in the Middle East, disclosed and patched in Microsoft's October 2018 Patch Tuesday, and has public proof-of-concept code. It is confirmed exploited in the wild: it sits in CISA's Known Exploited Vulnerabilities catalog (added 2022-01-21) with known ransomware use, and EPSS assigns a 70% probability of exploitation within 30 days.
What to do: Apply Microsoft's October 2018 (or later) cumulative security updates to all affected Windows 7/8.1/RT 8.1/Windows 10 clients and Windows Server 2008-2019 systems, per the vendor instructions required by CISA's KEV catalog. Prioritize multi-user hosts such as terminal/RDS servers and workstations where users can run untrusted code, since the attack requires local code execution with user interaction. Systems still on Windows 7/8.1 or Server 2008/2008 R2/2012 should be moved to Extended Security Updates or upgraded, and defenders should hunt for signs of FruityArmor-style activity on long-lived unpatched hosts.
| microsoft Windows 10 | 1507, 1607, 1703, 1709, 1803, 1809 |
| microsoft Windows 7 | all supported releases as listed by Microsoft |
| microsoft Windows 8.1 | all supported releases as listed by Microsoft |
| microsoft Windows RT 8.1 | all supported releases as listed by Microsoft |
| microsoft Windows Server 2008 | 2008 and 2008 R2 |
| microsoft Windows Server 2012 | 2012 and 2012 R2 |
| microsoft Windows Server 2016 | all supported releases as listed by Microsoft |
| microsoft Windows Server 2019 | all supported releases as listed by Microsoft |
| microsoft Windows Server (Semi-Annual Channel) | 1709, 1803 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
- Affected
- Microsoft Win32k
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1703, windows 10 1709, windows 10 1803, windows 10 1809, windows 7, windows 8.1, windows rt 8.1, windows server 1709, windows server 1803, windows server 2008
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H