CVE-2018-8639CISA KEV
Microsoft Windows Win32k Improper Resource Shutdown or Release Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
Microsoft Windows Win32k contains an improper resource shutdown or release vulnerability that allows for local, authenticated privilege escalation. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.
- Product
- Windows
- Added to KEV
- 3 Mar 2025
- Federal remediation due
- 24 Mar 2025
- Known ransomware use
- Yes