← Back to browse · API

CVE-2018-8120

Severity
HIGH
CVSS
7.0
EPSS
0.73721
Risk score
78.8
CISA KEV
Yes
PoC
No
Published
2022-03-15
Modified
2022-03-15
First seen
2026-08-07
Aliases
EUVD-2018-19796, GHSA-V82R-2HH9-72G8
Products
Microsoft:Win32k, Microsoft:Windows 7 32-bit Systems Service Pack 1, Microsoft:Windows 7 x64-based Systems Service Pack 1, Microsoft:Windows Server 2008 32-bit Systems Service Pack 2, Microsoft:Windows Server 2008 32-bit Systems Service Pack 2 (Server Core installation), Microsoft:Windows Server 2008 Itanium-Based Systems Service Pack 2, Microsoft:Windows Server 2008 R2 Itanium-Based Systems Service Pack 1, Microsoft:Windows Server 2008 R2 x64-based Systems Service Pack 1, Microsoft:Windows Server 2008 R2 x64-based Systems Service Pack 1 (Server Core installation), Microsoft:Windows Server 2008 x64-based Systems Service Pack 2, Microsoft:Windows Server 2008 x64-based Systems Service Pack 2 (Server Core installation)
Sources
euvd EUVD-2018-19796
cisa.gov CVE-2018-8120

Description

A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory.

References