Junglewise Threat Intelligence

CVE-2018-8406: Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability

CVE-2018-8406 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-03-28

Technologies: Microsoft Windows Server 2016, Microsoft Windows 10. Vendors: Microsoft.

Executive brief

An elevation of privilege vulnerability exists in the Microsoft DirectX Graphics Kernel (DXGKRNL) driver due to improper handling of objects in memory. A local attacker could exploit this to gain elevated system privileges.

Affected products

  • Microsoft Windows 10 1507, 1607, 1703, 1709, 1803
  • Microsoft Windows Server 2016 1709, 1803

Timeline

  • 2018-09-11: disclosed: Initial Microsoft advisory publication date (implied by CVE year and patch cycle)
  • 2018-09-11: patched: Microsoft released security updates to address this vulnerability.
  • 2022-03-28: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.

Related threats