Description
This module exploits elevation of privilege vulnerability that exists in Windows 7 and 2008 R2 when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
This module is tested against windows 7 x86, windows 7 x64 and windows server 2008 R2 standard x64.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/windows/local/ms18_8120_win32k_privescmsf undefined(ms18_8120_win32k_privesc) > show actions ...actions...msf undefined(ms18_8120_win32k_privesc) > set ACTION < action-name >msf undefined(ms18_8120_win32k_privesc) > show options ...show and set options...msf undefined(ms18_8120_win32k_privesc) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub