Lucene search

K
cve[email protected]CVE-2018-8589
HistoryNov 14, 2018 - 1:29 a.m.

CVE-2018-8589

2018-11-1401:29:02
web.nvd.nist.gov
880
In Wild
cve-2018-8589
elevation of privilege
win32k.sys
windows server 2008
windows 7
windows server 2008 r2
nvd

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

48.2%

An elevation of privilege vulnerability exists when Windows improperly handles calls to Win32k.sys, aka “Windows Win32k Elevation of Privilege Vulnerability.” This affects Windows Server 2008, Windows 7, Windows Server 2008 R2.

Affected configurations

Vulners
NVD
Node
microsoftwindows_server_2008Match32-bit Systems Service Pack 2
OR
microsoftwindows_server_2008Match32-bit Systems Service Pack 2 (Server Core installation)
OR
microsoftwindows_server_2008MatchItanium-Based Systems Service Pack 2
OR
microsoftwindows_server_2008Matchx64-based Systems Service Pack 2
OR
microsoftwindows_server_2008Matchx64-based Systems Service Pack 2 (Server Core installation)
OR
microsoftwindows_7Match32-bit Systems Service Pack 1
OR
microsoftwindows_7Matchx64-based Systems Service Pack 1
OR
microsoftwindows_server_2008_r2MatchItanium-Based Systems Service Pack 1
OR
microsoftwindows_server_2008_r2Matchx64-based Systems Service Pack 1
OR
microsoftwindows_server_2008_r2Matchx64-based Systems Service Pack 1 (Server Core installation)
VendorProductVersionCPE
microsoftwindows_server_200832-bit Systems Service Pack 2cpe:2.3:o:microsoft:windows_server_2008:32-bit Systems Service Pack 2:*:*:*:*:*:*:*
microsoftwindows_server_200832-bit Systems Service Pack 2 (Server Core installation)cpe:2.3:o:microsoft:windows_server_2008:32-bit Systems Service Pack 2 (Server Core installation):*:*:*:*:*:*:*
microsoftwindows_server_2008Itanium-Based Systems Service Pack 2cpe:2.3:o:microsoft:windows_server_2008:Itanium-Based Systems Service Pack 2:*:*:*:*:*:*:*
microsoftwindows_server_2008x64-based Systems Service Pack 2cpe:2.3:o:microsoft:windows_server_2008:x64-based Systems Service Pack 2:*:*:*:*:*:*:*
microsoftwindows_server_2008x64-based Systems Service Pack 2 (Server Core installation)cpe:2.3:o:microsoft:windows_server_2008:x64-based Systems Service Pack 2 (Server Core installation):*:*:*:*:*:*:*
microsoftwindows_732-bit Systems Service Pack 1cpe:2.3:o:microsoft:windows_7:32-bit Systems Service Pack 1:*:*:*:*:*:*:*
microsoftwindows_7x64-based Systems Service Pack 1cpe:2.3:o:microsoft:windows_7:x64-based Systems Service Pack 1:*:*:*:*:*:*:*
microsoftwindows_server_2008_r2Itanium-Based Systems Service Pack 1cpe:2.3:o:microsoft:windows_server_2008_r2:Itanium-Based Systems Service Pack 1:*:*:*:*:*:*:*
microsoftwindows_server_2008_r2x64-based Systems Service Pack 1cpe:2.3:o:microsoft:windows_server_2008_r2:x64-based Systems Service Pack 1:*:*:*:*:*:*:*
microsoftwindows_server_2008_r2x64-based Systems Service Pack 1 (Server Core installation)cpe:2.3:o:microsoft:windows_server_2008_r2:x64-based Systems Service Pack 1 (Server Core installation):*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Windows Server 2008",
    "vendor": "Microsoft",
    "versions": [
      {
        "status": "affected",
        "version": "32-bit Systems Service Pack 2"
      },
      {
        "status": "affected",
        "version": "32-bit Systems Service Pack 2 (Server Core installation)"
      },
      {
        "status": "affected",
        "version": "Itanium-Based Systems Service Pack 2"
      },
      {
        "status": "affected",
        "version": "x64-based Systems Service Pack 2"
      },
      {
        "status": "affected",
        "version": "x64-based Systems Service Pack 2 (Server Core installation)"
      }
    ]
  },
  {
    "product": "Windows 7",
    "vendor": "Microsoft",
    "versions": [
      {
        "status": "affected",
        "version": "32-bit Systems Service Pack 1"
      },
      {
        "status": "affected",
        "version": "x64-based Systems Service Pack 1"
      }
    ]
  },
  {
    "product": "Windows Server 2008 R2",
    "vendor": "Microsoft",
    "versions": [
      {
        "status": "affected",
        "version": "Itanium-Based Systems Service Pack 1"
      },
      {
        "status": "affected",
        "version": "x64-based Systems Service Pack 1"
      },
      {
        "status": "affected",
        "version": "x64-based Systems Service Pack 1 (Server Core installation)"
      }
    ]
  }
]

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

48.2%