CVE-2018-8639
KEV ransomwaremassKernel-mode privilege escalation in Microsoft Windows Win32k
CISA: Microsoft Windows Win32k Improper Resource Shutdown or Release Vulnerability
CVE-2018-8639 is an improper resource shutdown or release flaw (CWE-404) in the Windows Win32k kernel component. A local, authenticated attacker can trigger the faulty resource handling and leverage it to execute arbitrary code in kernel mode, the highest privilege level on a Windows system. Successful exploitation effectively yields full system control (SYSTEM-equivalent), making it useful both for escalating from a low-privileged foothold and as a step in post-compromise activity, including ransomware operations. All Microsoft Windows versions covered by the vendor's advisory for this CVE are affected; the source data does not specify exact version ranges. The flaw is confirmed exploited in the wild: it was added to the CISA Known Exploited Vulnerabilities catalog on 2025-03-03 with known ransomware use, and EPSS estimates a 22.2% probability of exploitation within 30 days (98th percentile), though no public proof-of-concept is known.
What to do: Apply Microsoft's security updates for all affected Windows releases immediately per vendor instructions, prioritizing servers, shared workstations, and systems where untrusted users can run code, since the flaw is in the CISA KEV catalog with known ransomware use. Follow applicable BOD 22-01 guidance for cloud services, or discontinue use where mitigations are unavailable. Until patched, restrict local code execution by untrusted accounts and monitor for unusual privilege-escalation activity.
| Microsoft Windows | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8641.
- Affected
- Microsoft Windows
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Known
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1703, windows 10 1709, windows 10 1803, windows 10 1809, windows 7, windows 8.1, windows rt 8.1, windows server 2008, windows server 2012, windows server 2016
- Weakness
- CWE-404
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H