CVE-2018-8120
Microsoft Win32k Privilege Escalation Vulnerability
7.0
CVSS 3.1
73.4 %
EPSS (current)
2022-03-15
KEV addition
Yes
Ransomware
Timeline
Publication, first public exploit and KEV addition on a day axis.
Key facts
Vendor / product: Microsoft / Win32k
Published: 2018-05-09 · Due (CISA): 2022-04-05
CWE: CWE-404 · EU list: no
Exploit references (metadata only)
| Source | Reference | Title | Date |
|---|---|---|---|
| metasploit | exploit/windows/local/ms18_8120_win32k_privesc | exploit/windows/local/ms18_8120_win32k_privesc | 2018-05-09 |
| exploitdb | 45653 | Microsoft Windows - SetImeInfoEx Win32k NULL Pointer Dereference (Metasploit) | 2018-10-22 |
References only — no downloads or instructions.