VYPR
High severity7.8CISA KEVNVD Advisory· Published Nov 14, 2018· Updated Jun 17, 2026

CVE-2018-8589

CVE-2018-8589

Description

An elevation of privilege vulnerability exists when Windows improperly handles calls to Win32k.sys, aka "Windows Win32k Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2.

Affected products

8
  • cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*
    • (no CPE)range: 32-bit Systems Service Pack 1
  • cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*+ 4 more
    • cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*
    • cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:itanium:*
    • cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*
    • (no CPE)range: 32-bit Systems Service Pack 2
    • (no CPE)range: Itanium-Based Systems Service Pack 1

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.