Vulnerability record · CVE-2018-8589 · published 14 November 2018
CVE-2018-8589: Windows Win32k.sys Elevation of Privilege
Microsoft · Windows 7
Windows improperly handles calls to Win32k.sys, creating an elevation of privilege flaw. The record names Windows Server 2008, Windows 7 and Windows Server 2008 R2 as affected. Because it is a kernel-level privilege escalation, successful abuse lets a low-privileged local user gain higher rights on the host.
Description
An elevation of privilege vulnerability exists when Windows improperly handles calls to Win32k.sys, aka "Windows Win32k Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw is confirmed exploited in the wild per CISA KEV and gives full kernel-level privilege escalation, though it requires an existing local foothold and affects only legacy Windows versions.
What it is
Windows improperly handles calls to Win32k.sys, creating an elevation of privilege flaw. The record names Windows Server 2008, Windows 7 and Windows Server 2008 R2 as affected. Because it is a kernel-level privilege escalation, successful abuse lets a low-privileged local user gain higher rights on the host.
Impact
An attacker who already has a foothold on the machine can escalate from a normal user to SYSTEM or kernel-level privileges. That level of access enables full control of the host, including credential theft and disabling security controls.
Attack surface
The CVSS vector is local (AV:L) with low privileges required (PR:L) and no user interaction (UI:N), so the flaw is reached by running code on the target system rather than over the network. No authentication beyond an existing local session is needed.
Exploitation
CVE-2018-8589 is listed in CISA's Known Exploited Vulnerabilities catalog, added 2022-05-23, which confirms exploitation in the wild. EPSS gives a 30-day probability of 0.03023 (86.8th percentile), and CISA records no known ransomware campaign use.
What to do
- Apply the Microsoft security update referenced in the vendor advisory for CVE-2018-8589 as the first action.
- Retire or isolate Windows 7, Windows Server 2008 and Windows Server 2008 R2, which are past end of support and no longer receive routine fixes.
- Restrict local interactive logon and limit who can run code on affected hosts to reduce the low-privileged foothold needed to trigger the flaw.
- Enable exploit protection features such as kernel ASLR and block untrusted drivers or unsigned code where feasible.
Detection
- Monitor for unexpected privilege changes, such as processes gaining SYSTEM or kernel-level tokens from a non-administrative context.
- Alert on suspicious or unsigned drivers and unusual Win32k.sys-related activity on affected Windows versions.
- Hunt for post-exploitation behavior on Windows 7 and Server 2008/R2 hosts, including credential dumping and security tool tampering.
- Correlate local logon events with subsequent high-integrity process creation on hosts that cannot be patched.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2018-8589 to the Known Exploited Vulnerabilities catalog on 23 May 2022 as "Microsoft Win32k Privilege Escalation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 13 June 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/105796 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1042140 | Broken LinkThird Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8589 | PatchVendor Advisory |
| http://www.securityfocus.com/bid/105796 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1042140 | Broken LinkThird Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8589 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-8589 | US Government Resource |
Track CVE-2018-8589 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-8589), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.