Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Mar 24, 2025

CVE-2018-8639

High
EPSS 31.9%CISA KEVRansomware
Microsoft/Windows

Description

Microsoft Windows Win32k contains an improper resource shutdown or release vulnerability that allows for local, authenticated privilege escalation. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.

EPSS — Exploit Probability

31.9%

Higher than 96.7% of all CVEs

Required Action

https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2018-8639 ; https://nvd.nist.gov/vuln/detail/CVE-2018-8639

Risk Assessment

HIGH
In CISA KEV
Ransomware

Details

Severity
High
EPSS
31.9%
CISA KEV
Yes
Ransomware
Known
Articles
0

Timeline

Published

Mar 3, 2025

Added to KEV

Mar 3, 2025

Remediation Due

Mar 24, 2025

Affected Product

Microsoft

Windows

View all Microsoft CVEs