CVE-2018-8399

high

Description

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 10 Servers, Windows 10. This CVE ID is unique from CVE-2018-8404.

References

http://www.securityfocus.com/bid/104998

http://www.securitytracker.com/id/1041466

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8399

Details

Source: MITRE

Published: 2018-08-15

Updated: 2019-10-03

Type: CWE-404

Risk Information

CVSS v2

Base Score: 6.9

Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 3.4

Severity: MEDIUM

CVSS v3

Base Score: 7

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 1

Severity: HIGH