CVE-2018-8589CISA KEV
Microsoft Win32k Privilege Escalation Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
A privilege escalation vulnerability exists when Windows improperly handles calls to Win32k.sys. An attacker who successfully exploited this vulnerability could run remote code in the security context of the local system.
- Product
- Win32k
- Added to KEV
- 23 May 2022
- Federal remediation due
- 13 Jun 2022
- Known ransomware use
- Not reported