LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2018-8120: Microsoft Win32k Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 15, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Apr 5, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2018-8120 to its Known Exploited Vulnerabilities catalog on Mar 15, 2022, with a federal patch deadline of Apr 5, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory.

CVE-2018-8120 is a privilege escalation vulnerability in the Microsoft Win32k component. When Win32k fails to properly handle objects in memory, an attacker who already has a foothold on a Windows system can elevate privileges. This matters because elevated access lets an adversary disable defenses, move laterally, or deploy further payloads. Public reporting indicates this vulnerability has been used by ransomware operators, so unpatched systems remain a practical risk.

Defenders should treat it as a local elevation issue on Windows hosts that include the Win32k subsystem. Confirm exact affected builds and patch status only against the vendor advisory; do not rely on secondary summaries alone.

How it works

The weakness is categorized under CWE-404 and centers on improper handling of objects in memory by Win32k. Win32k is the kernel-mode component that supports the Windows graphical and windowing subsystem. When object lifetime or cleanup is mishandled, an attacker with the ability to run code in a less-privileged context can trigger the flaw to obtain higher privileges on the same machine.

In practical terms, the attacker does not need a remote network service exposure for the core elevation step; they need local code execution first (for example via a malicious document, installer, or prior compromise). Once elevated, they can act with system-level rights. Exact trigger conditions, memory objects involved, and exploitation mechanics are not detailed here; teams must review the vendor advisory for authoritative technical description and any proof-of-concept restrictions.

Am I affected? How to find it in your systems

Win32k ships as part of Windows client and server installations that provide the desktop/windowing stack. It is present on typical endpoints, jump hosts, Remote Desktop Session Hosts, and many server SKUs unless a highly specialized configuration has removed graphical components.

If your asset data cannot confirm patch level, assume the host may still be exposed until verified.

How to remediate

Patch first. Apply the Microsoft updates that address CVE-2018-8120 exactly as directed in the vendor advisory and CISA guidance (“Apply updates per vendor instructions”). Use your standard patch pipeline (WSUS, ConfigMgr, Intune, or equivalent) and verify installation success via update history or compliance reports.

If you can't patch immediately

Compensating controls buy time but do not replace the vendor fix.

If your data may have been exposed

Actively exploited privilege-escalation flaws are frequently chained into broader compromises and ransomware incidents. If you have evidence of exploitation or cannot rule out compromise on unpatched hosts, follow your incident-response process: isolate affected systems, preserve volatile evidence, rotate credentials that may have been accessible from the elevated context, and hunt for persistence and lateral movement. As an additional personal check, individuals can run a free exposure scan of their email addresses against known breach data sets to see whether their credentials have appeared in prior public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Win32k
WeaknessCWE-404
Added to CISA KEVMar 15, 2022
Federal patch deadlineApr 5, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities