AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2018-8440

HIGH · CVSS 7.8 EPSS 18.39% CISA KEV · Actively Exploited

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-09-13 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CISA KEV Details

Status: This CVE is listed in CISA's Known Exploited Vulnerabilities catalog.

Ransomware use: Known

Added to KEV: 2022-03-28

Required action: Apply updates per vendor instructions.

CVE
CVE-2018-8440
Severity
HIGH
CVSS
7.8
EPSS
18.39%
Windows

Original NVD Description

An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC), aka "Windows ALPC Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.