Vulnerability record · CVE-2018-8120 · published 9 May 2018
CVE-2018-8120: Windows Win32k memory handling privilege escalation
Microsoft · Windows 7
The Win32k component in Windows fails to properly handle objects in memory, allowing a local attacker to elevate privileges. It affects Windows 7, Windows Server 2008 and Windows Server 2008 R2, all legacy platforms that still appear in some environments. Because Win32k is a core kernel component, a successful exploit gives full control of the host.
Description
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2. This CVE ID is unique from CVE-2018-8124, CVE-2018-8164, CVE-2018-8166.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is a KEV-listed local privilege escalation with known ransomware use, a public exploit and very high EPSS, but it requires an existing foothold and affects only legacy Windows versions.
What it is
The Win32k component in Windows fails to properly handle objects in memory, allowing a local attacker to elevate privileges. It affects Windows 7, Windows Server 2008 and Windows Server 2008 R2, all legacy platforms that still appear in some environments. Because Win32k is a core kernel component, a successful exploit gives full control of the host.
Impact
An attacker who already has a foothold on the machine gains kernel-level code execution and can run code as SYSTEM, install software, and persist. This turns a limited local account into full administrative control of the host.
Attack surface
The CVSS vector is local (AV:L) with low privileges required (PR:L) and no user interaction (UI:N), so the attacker must already be able to run code on the target. It is not reachable remotely and does not require a victim to open a file or click anything.
Exploitation
CVE-2018-8120 is listed in CISA KEV with known ransomware campaign use, and EPSS gives a 30-day probability of roughly 0.73 (99th percentile). A public exploit exists on Exploit-DB, so working code is available.
What to do
- Apply the Microsoft security update for CVE-2018-8120 on all affected Windows 7, Server 2008 and Server 2008 R2 systems; treat this as the first action.
- Where legacy systems cannot be patched, isolate them on segmented networks and restrict interactive logon and local code execution to trusted administrators.
- Remove or tightly control local accounts and tools that let low-privileged users run arbitrary code, since that is the prerequisite for this exploit.
- Prioritize remediation on any affected host that also shows signs of prior compromise or unusual process activity.
- Track KEV due dates and confirm patched status rather than relying on version inventory alone.
Detection
- Alert on unexpected processes spawning with SYSTEM integrity from non-service parents, especially on Windows 7 and Server 2008 hosts.
- Monitor for known public exploit artifacts and for unusual Win32k-related crashes or memory corruption events in system logs.
- Hunt for privilege escalation tooling and post-exploitation behavior such as new local admin creation, service installation, or credential dumping shortly after a low-privileged logon.
- Correlate KEV-listed CVE exposure with endpoint telemetry to find unpatched legacy hosts still running the affected OS versions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2018-8120 to the Known Exploited Vulnerabilities catalog on 15 March 2022 as "Microsoft Win32k Privilege Escalation Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 5 April 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/104034 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1040849 | Broken LinkThird Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8120 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/45653/ | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/104034 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1040849 | Broken LinkThird Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8120 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/45653/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-8120 | US Government Resource |
Track CVE-2018-8120 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-8120), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.