Zero-day exploit (CVE-2018-8453) used in targeted attacks
#1
Lightbulb 
[Image: 180910-zeroday-exploit-1.png]
Quote:Yesterday, Microsoft published their security bulletin, which patches CVE-2018-8453, among others. It is a vulnerability in win32k.sys discovered by Kaspersky Lab in August. We reported this vulnerability to Microsoft on August 17, 2018. Microsoft confirmed the vulnerability and designated it CVE-2018-8453.

In August 2018 our Automatic Exploit Prevention (AEP) systems detected an attempt to exploit a vulnerability in Microsoft Windows operating system. Further analysis into this case led us to uncover a zero-day vulnerability in win32k.sys. The exploit was executed by the first stage of a malware installer to get necessary privileges for persistence on the victim’s system. The code of the exploit is of high quality and written with the aim of reliably exploiting as many different MS Windows builds as possible, including MS Windows 10 RS4.

So far, we detected a very limited number of attacks using this vulnerability. The victims are located in the Middle East.
Full reading: https://securelist.com/cve-2018-8453-use...cks/88151/
[-] The following 1 user says Thank You to harlan4096 for this post:
  • silversurfer
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
CrystalDiskInfo 9.9.0 [2026/05/18]
CrystalDiskInfo 9....harlan4096 — 06:43
Adobe Acrobat Reader DC 2026.001.21563
Adobe Acrobat Read...harlan4096 — 06:42
FastCopy 5.11.3
FastCopy 5.11.3: ...harlan4096 — 06:40
QOwnNotes
26.5.12 Added a n...Kool — 03:51
AnyViewer 3.6.0 for macOS
AnyViewer 3.6.0 fo...harlan4096 — 10:44

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (39)axuben
avatar (40)ihijudu
avatar (50)Mirzojap
avatar (36)idilysaju
avatar (40)odukoromu
avatar (46)Joanna4589

[-]
Online Staff
leemaek's profile leemaek

>