CVE-2018-8120
Summary
| CVE | CVE-2018-8120 |
|---|---|
| State | PUBLISHED |
| Assigner | microsoft |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-05-09 19:29:01 UTC |
| Updated | 2026-08-13 05:17:18 UTC |
| Description | An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2. This CVE ID is unique from CVE-2018-8124, CVE-2018-8164, CVE-2018-8166. |
Risk And Classification
Primary CVSS: v3.1 7 HIGH from [email protected]
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.737210000 probability, percentile 0.994280000 (date 2026-08-13)
CISA KEV: Listed on 2022-03-15; due 2022-04-05; ransomware use Known
Problem Types: CWE-404 | Elevation of Privilege | CWE-404 CWE-404 Improper Resource Shutdown or Release
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 7 | HIGH | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | ADP | DECLARED | 7 | HIGH | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 7 | HIGH | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 7.2 | AV:L/AC:L/Au:N/C:C/I:C/A:C |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
HighPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:L/Au:N/C:C/I:C/A:C
CISA Known Exploited Vulnerability
| Vendor | Microsoft |
|---|---|
| Product | Win32k |
| Name | Microsoft Win32k Privilege Escalation Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://nvd.nist.gov/vuln/detail/CVE-2018-8120 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Microsoft | Windows 7 | - | sp1 | All | All |
| Operating System | Microsoft | Windows Server 2008 | - | sp2 | All | All |
| Operating System | Microsoft | Windows Server 2008 | r2 | sp1 | All | All |
| Operating System | Microsoft | Windows Server 2008 | r2 | sp1 | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Microsoft | Windows Server 2008 | affected 32-bit Systems Service Pack 2 | Not specified |
| CNA | Microsoft | Windows Server 2008 | affected 32-bit Systems Service Pack 2 (Server Core installation) | Not specified |
| CNA | Microsoft | Windows Server 2008 | affected Itanium-Based Systems Service Pack 2 | Not specified |
| CNA | Microsoft | Windows Server 2008 | affected x64-based Systems Service Pack 2 | Not specified |
| CNA | Microsoft | Windows Server 2008 | affected x64-based Systems Service Pack 2 (Server Core installation) | Not specified |
| CNA | Microsoft | Windows 7 | affected 32-bit Systems Service Pack 1 | Not specified |
| CNA | Microsoft | Windows 7 | affected x64-based Systems Service Pack 1 | Not specified |
| CNA | Microsoft | Windows Server 2008 R2 | affected Itanium-Based Systems Service Pack 1 | Not specified |
| CNA | Microsoft | Windows Server 2008 R2 | affected x64-based Systems Service Pack 1 | Not specified |
| CNA | Microsoft | Windows Server 2008 R2 | affected x64-based Systems Service Pack 1 (Server Core installation) | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Windows Kernel Multiple Flaws Let Local Users Bypass Security Restictions, Obtain Potentially Sensitive Information, and Gain Elevated Privileges on the Target System - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Broken Link, Third Party Advisory, VDB Entry |
| Microsoft Windows - SetImeInfoEx Win32k NULL Pointer Dereference (Metasploit) - Windows local Exploit | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | Exploit, Third Party Advisory, VDB Entry |
| Microsoft Windows Kernel 'Win32k.sys' CVE-2018-8120 Local Privilege Escalation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Broken Link, Third Party Advisory, VDB Entry |
| www.cisa.gov/known-exploited-vulnerabilities-catalog | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | www.cisa.gov | US Government Resource |
| portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8120 | af854a3a-2127-422b-91ae-364da2661108 | portal.msrc.microsoft.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| ADP | 2022-03-15T00:00:00.000Z | CVE-2018-8120 added to CISA KEV |
There are currently no legacy QID mappings associated with this CVE.