Buffer overflow in Microsoft Windows and Windows Server - CVE-2018-8589
Published: November 13, 2018 / Updated: June 2, 2020
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a boundary error within Win32k.sys driver. A local user can create a specially crafted application, run it on vulnerable system and execute code withe superuser privileges.
Note: this vulnerability is being actively exploited in limited targeted attacks.
Affected software
Windows Server