cve/2018/CVE-2018-8453.md

84 lines
4.6 KiB
Markdown
Raw Normal View History

2024-05-26 14:27:05 +02:00
### [CVE-2018-8453](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8453)
![](https://img.shields.io/static/v1?label=Product&message=Windows%2010%20Servers&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Windows%2010&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Windows%207&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Windows%208.1&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Windows%20RT%208.1&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Windows%20Server%202008%20R2&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Windows%20Server%202008&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Windows%20Server%202012%20R2&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Windows%20Server%202012&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Windows%20Server%202016&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Windows%20Server%202019&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=Elevation%20of%20Privilege&color=brighgreen)
### Description
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
### POC
#### Reference
- http://packetstormsecurity.com/files/153669/Microsoft-Windows-NtUserSetWindowFNID-Win32k-User-Callback.html
2024-06-09 00:33:16 +00:00
- http://packetstormsecurity.com/files/153669/Microsoft-Windows-NtUserSetWindowFNID-Win32k-User-Callback.html
2024-05-26 14:27:05 +02:00
- https://securelist.com/cve-2018-8453-used-in-targeted-attack
2024-06-09 00:33:16 +00:00
- https://securelist.com/cve-2018-8453-used-in-targeted-attack
2024-05-26 14:27:05 +02:00
#### Github
- https://github.com/0xT11/CVE-POC
- https://github.com/0xcyberpj/windows-exploitation
- https://github.com/0xpetros/windows-privilage-escalation
- https://github.com/ARPSyndicate/cvemon
- https://github.com/ASR511-OO7/windows-kernel-exploits
- https://github.com/Ascotbe/Kernelhub
- https://github.com/CVEDB/PoC-List
- https://github.com/CVEDB/awesome-cve-repo
- https://github.com/CVEDB/top
2024-05-27 13:12:02 +00:00
- https://github.com/Cruxer8Mech/Idk
2024-05-26 14:27:05 +02:00
- https://github.com/ExpLife0011/awesome-windows-kernel-security-development
- https://github.com/FULLSHADE/WindowsExploitationResources
- https://github.com/GhostTroops/TOP
- https://github.com/JERRY123S/all-poc
- https://github.com/Jkrasher/WindowsThreatResearch_JKrasher
- https://github.com/LegendSaber/exp_x64
- https://github.com/Micr067/windows-kernel-exploits
- https://github.com/Mkv4/cve-2018-8453-exp
- https://github.com/NitroA/windowsexpoitationresources
- https://github.com/NullArray/WinKernel-Resources
- https://github.com/Ondrik8/exploit
- https://github.com/Ostorlab/KEV
- https://github.com/Ostorlab/known_exploited_vulnerbilities_detectors
- https://github.com/QChiLan/win-exploit
- https://github.com/SecWiki/windows-kernel-exploits
- https://github.com/SexyBeast233/SecBooks
- https://github.com/TamilHackz/windows-exploitation
- https://github.com/albinjoshy03/windows-kernel-exploits
- https://github.com/alian87/windows-kernel-exploits
- https://github.com/alphaSeclab/sec-daily-2019
- https://github.com/asr511/windows-kernel-exploits
- https://github.com/cyberanand1337x/bug-bounty-2022
- https://github.com/demilson/Windows
- https://github.com/distance-vector/window-kernel-exp
- https://github.com/hectorgie/PoC-in-GitHub
- https://github.com/hktalent/TOP
- https://github.com/jbmihoub/all-poc
- https://github.com/lyshark/Windows-exploits
- https://github.com/mishmashclone/SecWiki-windows-kernel-exploits
- https://github.com/nicolas-gagnon/windows-kernel-exploits
- https://github.com/paramint/windows-kernel-exploits
- https://github.com/pravinsrc/NOTES-windows-kernel-links
- https://github.com/renzu0/Windows-exp
- https://github.com/root26/bug
- https://github.com/safesword/WindowsExp
- https://github.com/thepwnrip/leHACK-Analysis-of-CVE-2018-8453
- https://github.com/valentinoJones/Windows-Kernel-Exploits
- https://github.com/weeka10/-hktalent-TOP
- https://github.com/xfinest/windows-kernel-exploits
- https://github.com/ycdxsb/WindowsPrivilegeEscalation
- https://github.com/yige666/windows-kernel-exploits
- https://github.com/yisan1/hh
- https://github.com/yiyebuhuijia/windows-kernel-exploits
- https://github.com/ze0r/cve-2018-8453-exp