← Browse

CVE-2018-8589

Act now ● On CISA KEV — actively exploited

Actively exploited — on the CISA KEV list.

CVSS base
EPSS — probability of exploitation (30 days)
3.0%
86.8th percentile
CISA KEV
Listed
Added 2022-05-23 · patch by 2022-06-13
Weakness / dates
Published — · modified —

Description

A privilege escalation vulnerability exists when Windows improperly handles calls to Win32k.sys. An attacker who successfully exploited this vulnerability could run remote code in the security context of the local system.

Official: NVD · CVE.org