CVE-2018-8453
Microsoft Win32k Privilege Escalation Vulnerability
- Published
- Oct 10, 2018
- Updated
- Aug 13, 2026
- Assigning CNA
- microsoft
- Evidence observed
- Jul 17, 2019
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HHigh · next 30 days
- Percentile
- 99.4%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Sources
5- leHACK-Analysis-of-CVE-2018-8453Research
Conference talk analyzing CVE-2018-8453, a Windows kernel UAF and double-free vulnerability. Covers binary diffing, exploit reproduction, heap spray, and data-only attacks across Windows 7, 8.1, and 10.
- cve-2018-8453-expExploit
cve-2018-8453 exp
- cve-2018-8453-expExploit
cve-2018-8453 exp
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.