← KEV catalog
CISA known exploited vulnerability

CVE-2018-8589

Microsoft Win32k Privilege Escalation Vulnerability

SOURCE FACT

Microsoft · Win32k

A privilege escalation vulnerability exists when Windows improperly handles calls to Win32k.sys. An attacker who successfully exploited this vulnerability could run remote code in the security context of the local system.

Required action

Apply updates per vendor instructions.

CISA notes

https://nvd.nist.gov/vuln/detail/CVE-2018-8589

View source evidence →

CHECK YOUR OUTSIDE-IN INVENTORY

Could this product be present?