LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2018-8440: Microsoft Windows Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 28, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Apr 18, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2018-8440 to its Known Exploited Vulnerabilities catalog on Mar 28, 2022, with a federal patch deadline of Apr 18, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC).

CVE-2018-8440 is a privilege-escalation vulnerability in Microsoft Windows. It arises when the operating system improperly handles calls to Advanced Local Procedure Call (ALPC). An attacker who already has a foothold on a system can abuse this flaw to gain higher privileges, which matters because elevated access often enables further lateral movement, persistence, or deployment of ransomware. CISA notes known ransomware use of this vulnerability, so timely remediation is essential for any Windows environment.

How it works

The core issue is improper handling of ALPC calls. ALPC is a Windows inter-process communication mechanism used by many system components. When those calls are not validated or restricted correctly, a lower-privileged process can influence higher-privileged ones. In practice, an attacker who can already run code as a standard user or service account crafts ALPC interactions that cause the system to grant elevated rights. Exact exploit mechanics and preconditions vary by Windows build and configuration; defenders should treat this as a classic local elevation-of-privilege weakness and confirm full technical details against the vendor advisory rather than relying on incomplete public descriptions.

Am I affected? How to find it in your systems

This vulnerability affects Microsoft Windows. It can appear on workstations, servers, and any other Windows host that processes ALPC traffic—essentially the majority of Windows deployments. Inventory steps:

Because the CWE is not specified in the provided record, treat detection as version- and configuration-driven rather than signature-driven until the advisory supplies more detail.

How to remediate

Patch first. Apply the security updates Microsoft released for CVE-2018-8440 exactly as described in the vendor advisory and follow CISA’s required action: “Apply updates per vendor instructions.” After installation:

If you can't patch immediately

Until the vendor update can be deployed, reduce risk with compensating controls:

These measures buy time but do not replace the official patch.

If your data may have been exposed

Actively exploited privilege-escalation vulnerabilities are frequently chained into broader compromises and ransomware incidents. If you have evidence of exploitation or simply want to check whether credentials tied to your organization already appear in known breach data, run a free exposure scan of your email addresses against public breach corpora. That check is only one indicator; continue full incident-response procedures, credential rotation, and forensic review of any affected hosts.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
Added to CISA KEVMar 28, 2022
Federal patch deadlineApr 18, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities