High severity7.8CISA KEVNVD Advisory· Published Nov 14, 2018· Updated Jun 17, 2026
CVE-2018-8589
CVE-2018-8589
Description
An elevation of privilege vulnerability exists when Windows improperly handles calls to Win32k.sys, aka "Windows Win32k Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2.
Affected products
8cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*+ 4 more
- cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:itanium:*
- cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*
- (no CPE)range: 32-bit Systems Service Pack 2
- (no CPE)range: Itanium-Based Systems Service Pack 1
Patches
Vulnerability mechanics
References
4- portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8589nvdPatchVendor Advisory
- www.securityfocus.com/bid/105796nvdBroken LinkThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1042140nvdBroken LinkThird Party AdvisoryVDB Entry
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
0No linked articles in our index yet.