A AegiFlow
UNKNOWNKNOWN EXPLOITED

CVE-2018-8589

Microsoft Win32k Privilege Escalation Vulnerability

Published
2022-05-23
Modified
2026-07-31
Sources
cisa-kev

Summary

A privilege escalation vulnerability exists when Windows improperly handles calls to Win32k.sys. An attacker who successfully exploited this vulnerability could run remote code in the security context of the local system.

References

Includes data from the CISA Known Exploited Vulnerabilities catalog.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.