CVE-2018-8639Active Exploitation(microsoft / windows_10_1507)

HIGHCVSS 7.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Patch microsoft windows_10_1507 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8641.

6.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-03-24. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-404

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1507
  • windows_10_1607
  • windows_10_1703
  • windows_10_1709

Threat summary

  • Active exploitation appears in 3 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 2 observed days

What's happening

  • Active exploitation reported across 3 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Peaked at 3 mentions on most recent observed day (2026-04-29)
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
windows_10_1507windows_10_1607windows_10_1703windows_10_1709windows_10_1803windows_10_1809windows_7windows_8.1windows_rt_8.1windows_server_2008

2 versions affected across 13 products

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-02-03: 1Mentions · 2026-04-29: 3PoC Mentioned / Linked · 2026-02-03: 1Active Exploitation · 2026-02-03: 1Active Exploitation · 2026-04-29: 2Patch / Workaround · 2026-02-03: 1Patch / Workaround · 2026-04-29: 1Technical Details · 2026-02-03: 1Technical Details · 2026-04-29: 102-0304-29
Signal classification2 categories
Active Exploitation
375.0%
General
125.0%
Classification over time
DateTotalLabels
2026-02-031
Active Exploitation1
2026-04-293
Active Exploitation2General1
Full discourse4 posts
  • Ostorlab@OstorlabSec
    Active Exploitation

    🚨 CVE-2018-8639 : WINDOWS KERNEL LPE EXPLOIT ALERT 🚨 A critical local privilege escalation vulnerability has been disclosed in the Win32k kernel-mode driver (win32k.sys), allowing attackers to escalate from user-level execution to SYSTEM privileges. This flaw is actively exploited in ransomware and APT attack chains and is listed in CISA’s Known Exploited Vulnerabilities (KEV) catalog. Risk Severity: - High (CVSS 7.8, active exploitation, public proof-of-concept available, ransomware usage observed) Impact: - Local privilege escalation to SYSTEM - Full kernel-level code execution - Disabling of security controls and EDR - Installation of persistent rootkits and bootkits - Complete system takeover and data exfiltration - Ransomware deployment at maximum privilege Root Cause: - CWE-416 (Use-After-Free). The win32k.sys kernel driver improperly manages the lifetime of window objects during user-mode callbacks. Attackers can free and reallocate kernel objects while references persist, leading to execution of attacker-controlled code in kernel context. Attackers can: - Escalate privileges from a standard user to SYSTEM - Execute arbitrary code in kernel mode - Bypass endpoint security protections - Establish stealthy persistence at the OS level - Chain the exploit with phishing or RCE for full compromise Are You Affected? - Vulnerable: Unpatched Windows 7, Windows 8.1, Windows 10 (1507–1809), Windows Server 2008 R2–2019 - Scope: Workstations, servers, and domain-joined systems lacking December 2018 security updates Immediate Action Required: - Update: Apply Microsoft’s December 11, 2018 security patches immediately (KB4471329 / KB4471330 / KB4471332 / KB4471324 / KB4467708 / KB4471322 as applicable) - Mitigation: Restrict local interactive access, enable VBS and HVCI, and remove unnecessary local admin privileges - Audit: Monitor for unexpected SYSTEM-level process creation, suspicious kernel driver activity, and signs of post-exploitation persistence Kernel privilege escalation bugs turn minor intrusions into total compromise. Patch legacy systems or isolate them immediately. 🛡️ #ostorlabCVE

    Post summary

    The post alerts that CVE‑2018‑8639, a kernel‑mode LPE flaw, is actively exploited in ransomware and APT campaigns, and urges immediate patching and mitigation.

    01020106
    582 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    Stay ahead of the curve with Lyrie's real-time threat analysis. Learn more about CVE-2018-8639 and see how we can help fortify your defenses: RIGHT NOW on X, 'Ransomware & Extortion' is trending!

    Post summary

    The post merely mentions CVE-2018-8639 in a promotional context without providing any technical or actionable information.

    1000025
    125 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CISA has just added CVE-2018-8639 (Windows Win32k LPE) to its Known Exploited Vulnerabilities list. This vulnerability is confirmed to be tied to ongoing ransomware campaigns. Defenders must prioritize patching this ASAP! 🔒

    Post summary

    CISA confirms CVE‑2018‑8639 is actively exploited in ransomware campaigns and urges rapid patching.

    1000031
    125 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    Ransomware is evolving rapidly! Organizations must stay alert as attackers exploit CVE-2018-8639. Regular vulnerability assessments and staff training on phishing can mitigate risks. Knowledge is power! ⚡

    Post summary

    The tweet states that attackers are actively exploiting CVE-2018-8639, emphasizing the importance of vulnerability assessments and staff phishing training.

    1000025
    125 followersView on X
CPE platform detail17 entries

17 of 17 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1507---
OSmicrosoftwindows_10_1607---
OSmicrosoftwindows_10_1703---
OSmicrosoftwindows_10_1709---
OSmicrosoftwindows_10_1803---
OSmicrosoftwindows_10_1809---
OSmicrosoftwindows_7---
OSmicrosoftwindows_8.1---
OSmicrosoftwindows_rt_8.1---
OSmicrosoftwindows_server_2008---
OSmicrosoftwindows_server_2008r2-itanium
OSmicrosoftwindows_server_2008r2-x64
OSmicrosoftwindows_server_2008r2--
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---

Explore more