Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Mar 24, 2025

High
CISA KEVRansomware

CVE-2018-8639

MicrosoftWindows

Microsoft Windows Win32k contains an improper resource shutdown or release vulnerability that allows for local, authenticated privilege escalation. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.

Required Action

https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2018-8639 ; https://nvd.nist.gov/vuln/detail/CVE-2018-8639

Vulnerability Overview

Severity
High
CISA KEV
Yes
Ransomware
Known
Published
Mar 3, 2025
KEV Added
Mar 3, 2025
Due Date
Mar 24, 2025
Related Articles
0

Vendor

Microsoft

Windows