VulnerabilityModified
CVE-2018-1038
The Windows kernel in Windows 7 SP1 and Windows Server 2008 R2 SP1 allows an elevation of privilege vulnerability due to the way it handles objects in memory, aka "Windows Kernel Elevation of Privilege Vulnerability."
HIGH 7.8EPSS 8.51%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (8.51%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Windows kernel in Windows 7 SP1 and Windows Server 2008 R2 SP1 allows an elevation of privilege vulnerability due to the way it handles objects in memory, aka "Windows Kernel Elevation of Privilege Vulnerability."
- CVSS 3.0
- 7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 8.51% probability · 95th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/windows 7 · microsoft/windows server 2008
- Source
- secure@microsoft.com
References
- http://www.securityfocus.com/bid/103549Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040632Third Party Advisory, VDB Entry
- https://blog.xpnsec.com/total-meltdown-cve-2018-1038/Exploit, Third Party Advisory
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-1038Patch, Vendor Advisory
- https://www.exploit-db.com/exploits/44581/Exploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/103549Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040632Third Party Advisory, VDB Entry
- https://blog.xpnsec.com/total-meltdown-cve-2018-1038/Exploit, Third Party Advisory
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-1038Patch, Vendor Advisory
- https://www.exploit-db.com/exploits/44581/Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.