ZeroHour

CVE-2018-8611

KEVmass

Local Privilege Escalation in Microsoft Windows Kernel Exploited in the Wild

CISA: Microsoft Windows Kernel Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
4%p90
Published
()
KEV added
AI analysis

CVE-2018-8611 is an elevation-of-privilege vulnerability in the Microsoft Windows kernel caused by improper handling of objects in memory (recorded as CWE-404, improper resource shutdown/release). It is a local flaw: an attacker who can already run code with limited privileges on a target machine can trigger it with a specially crafted application, with no user interaction required. Successful exploitation executes code in kernel context, elevating the attacker to SYSTEM/administrator and giving full control of the host, a typical post-initial-access step in ransomware chains. Nearly every Windows client and server version in support at disclosure is affected: Windows 7, 8.1, RT 8.1 and Windows 10 (1607 through 1809), plus Windows Server 2008 through 2019. The flaw is confirmed exploited in the wild, with CISA adding it to the KEV catalog on 2022-05-24 and an EPSS of 4.2% (90th percentile); the KEV record lists ransomware use as unknown, though public reporting ties a family of Windows kernel EoP exploits including this one to ransomware operators.

What to do: Apply Microsoft's December 2018 security update for CVE-2018-8611 on all affected Windows 7, 8.1, RT 8.1, 10 and Server 2008-2019 hosts; there is no known workaround and patching is the required CISA KEV action, so verify the December 2018 (or later) monthly rollup is installed. Prioritize servers and workstations where limited-privilege users or untrusted workloads run (RDS, application servers, shared endpoints), and treat any remaining unpatched Windows 7/8.1/legacy-Server machine as high risk because ransomware operators have been observed chaining Windows kernel EoP exploits like this one after initial access.

Affected
microsoft Windows 101607, 1703, 1709, 1803, 1809 (all editions in support at time of disclosure)
microsoft Windows 7all supported editions/service packs at time of disclosure
microsoft Windows 8.1all supported editions at time of disclosure
microsoft Windows RT 8.1all supported editions at time of disclosure
microsoft Windows Server 2008all supported editions at time of disclosure
microsoft Windows Server 2008 R2all supported editions at time of disclosure (named in the CISA description)
microsoft Windows Server 2012all supported editions at time of disclosure
microsoft Windows Server 2012 R2all supported editions at time of disclosure (named in the CISA description)
microsoft Windows Server 2016all supported editions at time of disclosure
microsoft Windows Server 2019all supported editions at time of disclosure
Estimated exposure
masshundreds of millions of Windows endpoints at time of disclosure (~700M active Windows 10 devices plus hundreds of millions of Windows 7 PCs), with residual… — Estimated from the Windows installed base at disclosure - Windows 10 alone reached roughly 700 million active devices in 2018 and Windows 7 still ran on the majority of business PCs - reduced today by years of patching so that mainly…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "Windows Kernel Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1607, windows 10 1703, windows 10 1709, windows 10 1803, windows 10 1809, windows 7, windows 8.1, windows rt 8.1, windows server 2008, windows server 2012, windows server 2016, windows server 2019
Weakness
CWE-404
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news