Skip to content
COOEY

EXPOSURES › CVE-2018-8639

CVE-2018-8639

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-03-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2018-8639 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwarerceexploited-in-wildunpatchedprivilege-escalationnegligence

A local, authenticated privilege escalation flaw in Windows Win32k allowed attackers to run arbitrary kernel-mode code, leading to ransomware outbreaks.

This vulnerability required local authentication but still enabled arbitrary kernel-mode code execution, a severe breach of trust for any organization running Windows. DIBs must ensure all Windows systems are patched against this KEV-listed flaw to prevent ransomware entry and privilege escalation. The failure highlights the risk of relying on local authentication as a security boundary when a kernel-mode exploit exists.

Shame score — A critical, actively exploited vulnerability in a foundational OS component that enabled ransomware attacks, demonstrating severe negligence in patch management and system hardening.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Microsoft Windows Win32k contains an improper resource shutdown or release vulnerability that allows for local, authenticated privilege escalation. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.

AFFECTED FEDRAMP PRODUCTS · 4
PRODUCTSTATUS
Azure Commercial Cloud
Microsoft
Authorized
Azure Government (includes Dynamics 365)
Microsoft
Authorized
Microsoft Office 365 GCC High
Microsoft
In Process
Office 365 Multi-Tenant & Supporting Services
Microsoft
Authorized