CVE-2018-8611
KEVmassLocal Privilege Escalation in Microsoft Windows Kernel Exploited in the Wild
CISA: Microsoft Windows Kernel Privilege Escalation Vulnerability
CVE-2018-8611 is an elevation-of-privilege vulnerability in the Microsoft Windows kernel caused by improper handling of objects in memory (recorded as CWE-404, improper resource shutdown/release). It is a local flaw: an attacker who can already run code with limited privileges on a target machine can trigger it with a specially crafted application, with no user interaction required. Successful exploitation executes code in kernel context, elevating the attacker to SYSTEM/administrator and giving full control of the host, a typical post-initial-access step in ransomware chains. Nearly every Windows client and server version in support at disclosure is affected: Windows 7, 8.1, RT 8.1 and Windows 10 (1607 through 1809), plus Windows Server 2008 through 2019. The flaw is confirmed exploited in the wild, with CISA adding it to the KEV catalog on 2022-05-24 and an EPSS of 4.2% (90th percentile); the KEV record lists ransomware use as unknown, though public reporting ties a family of Windows kernel EoP exploits including this one to ransomware operators.
What to do: Apply Microsoft's December 2018 security update for CVE-2018-8611 on all affected Windows 7, 8.1, RT 8.1, 10 and Server 2008-2019 hosts; there is no known workaround and patching is the required CISA KEV action, so verify the December 2018 (or later) monthly rollup is installed. Prioritize servers and workstations where limited-privilege users or untrusted workloads run (RDS, application servers, shared endpoints), and treat any remaining unpatched Windows 7/8.1/legacy-Server machine as high risk because ransomware operators have been observed chaining Windows kernel EoP exploits like this one after initial access.
| microsoft Windows 10 | 1607, 1703, 1709, 1803, 1809 (all editions in support at time of disclosure) |
| microsoft Windows 7 | all supported editions/service packs at time of disclosure |
| microsoft Windows 8.1 | all supported editions at time of disclosure |
| microsoft Windows RT 8.1 | all supported editions at time of disclosure |
| microsoft Windows Server 2008 | all supported editions at time of disclosure |
| microsoft Windows Server 2008 R2 | all supported editions at time of disclosure (named in the CISA description) |
| microsoft Windows Server 2012 | all supported editions at time of disclosure |
| microsoft Windows Server 2012 R2 | all supported editions at time of disclosure (named in the CISA description) |
| microsoft Windows Server 2016 | all supported editions at time of disclosure |
| microsoft Windows Server 2019 | all supported editions at time of disclosure |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "Windows Kernel Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1703, windows 10 1709, windows 10 1803, windows 10 1809, windows 7, windows 8.1, windows rt 8.1, windows server 2008, windows server 2012, windows server 2016, windows server 2019
- Weakness
- CWE-404
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H