### [CVE-2018-8453](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8453) ![](https://img.shields.io/static/v1?label=Product&message=Windows%2010%20Servers&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=Windows%2010&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=Windows%207&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=Windows%208.1&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=Windows%20RT%208.1&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=Windows%20Server%202008%20R2&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=Windows%20Server%202008&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=Windows%20Server%202012%20R2&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=Windows%20Server%202012&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=Windows%20Server%202016&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=Windows%20Server%202019&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=Elevation%20of%20Privilege&color=brighgreen) ### Description An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. ### POC #### Reference - http://packetstormsecurity.com/files/153669/Microsoft-Windows-NtUserSetWindowFNID-Win32k-User-Callback.html - http://packetstormsecurity.com/files/153669/Microsoft-Windows-NtUserSetWindowFNID-Win32k-User-Callback.html - https://securelist.com/cve-2018-8453-used-in-targeted-attack - https://securelist.com/cve-2018-8453-used-in-targeted-attack #### Github - https://github.com/0xT11/CVE-POC - https://github.com/0xcyberpj/windows-exploitation - https://github.com/0xpetros/windows-privilage-escalation - https://github.com/ARPSyndicate/cvemon - https://github.com/ASR511-OO7/windows-kernel-exploits - https://github.com/Ascotbe/Kernelhub - https://github.com/CVEDB/PoC-List - https://github.com/CVEDB/awesome-cve-repo - https://github.com/CVEDB/top - https://github.com/Cruxer8Mech/Idk - https://github.com/ExpLife0011/awesome-windows-kernel-security-development - https://github.com/FULLSHADE/WindowsExploitationResources - https://github.com/GhostTroops/TOP - https://github.com/JERRY123S/all-poc - https://github.com/Jkrasher/WindowsThreatResearch_JKrasher - https://github.com/LegendSaber/exp_x64 - https://github.com/Micr067/windows-kernel-exploits - https://github.com/Mkv4/cve-2018-8453-exp - https://github.com/NitroA/windowsexpoitationresources - https://github.com/NullArray/WinKernel-Resources - https://github.com/Ondrik8/exploit - https://github.com/Ostorlab/KEV - https://github.com/Ostorlab/known_exploited_vulnerbilities_detectors - https://github.com/QChiLan/win-exploit - https://github.com/SecWiki/windows-kernel-exploits - https://github.com/SexyBeast233/SecBooks - https://github.com/TamilHackz/windows-exploitation - https://github.com/albinjoshy03/windows-kernel-exploits - https://github.com/alian87/windows-kernel-exploits - https://github.com/alphaSeclab/sec-daily-2019 - https://github.com/asr511/windows-kernel-exploits - https://github.com/cyberanand1337x/bug-bounty-2022 - https://github.com/demilson/Windows - https://github.com/distance-vector/window-kernel-exp - https://github.com/hectorgie/PoC-in-GitHub - https://github.com/hktalent/TOP - https://github.com/jbmihoub/all-poc - https://github.com/lyshark/Windows-exploits - https://github.com/mishmashclone/SecWiki-windows-kernel-exploits - https://github.com/nicolas-gagnon/windows-kernel-exploits - https://github.com/paramint/windows-kernel-exploits - https://github.com/pravinsrc/NOTES-windows-kernel-links - https://github.com/renzu0/Windows-exp - https://github.com/root26/bug - https://github.com/safesword/WindowsExp - https://github.com/thepwnrip/leHACK-Analysis-of-CVE-2018-8453 - https://github.com/valentinoJones/Windows-Kernel-Exploits - https://github.com/weeka10/-hktalent-TOP - https://github.com/xfinest/windows-kernel-exploits - https://github.com/ycdxsb/WindowsPrivilegeEscalation - https://github.com/yige666/windows-kernel-exploits - https://github.com/yisan1/hh - https://github.com/yiyebuhuijia/windows-kernel-exploits - https://github.com/ze0r/cve-2018-8453-exp