ZeroHour

CVE-2018-8405

KEV ransomwaremass

Local Privilege Escalation in Microsoft DirectX Graphics Kernel (DXGKRNL)

CISA: Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
3%p88
Published
()
KEV added
AI analysis

Microsoft's DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory, allowing a local attacker who can already execute code on a target machine to elevate privileges to kernel/SYSTEM level (CVSS 7.8, CWE-404). It is triggered by running a specially crafted local application against the vulnerable driver on affected Windows clients and servers; no remote or unauthenticated access is required. Successful exploitation yields full system compromise (confidentiality, integrity, and availability impact at the highest privilege level), and ransomware operators are known to chain such local privilege escalations onto an initial foothold. Affected products are Windows 8.1, Windows RT 8.1, Windows 10 builds 1507 through 1803, and Windows Server 2012, 2012 R2, 2016, and the Server 1709/1803 Semi-Annual Channel releases. The flaw was fixed in Microsoft's July 2018 security updates, but it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-28 with known ransomware use, confirming exploitation in the wild against unpatched systems.

What to do: Verify the July 2018 (or later) cumulative update or monthly rollup is installed on all Windows 8.1/RT 8.1, Windows 10 1507-1803, Windows Server 2012/2012 R2, 2016, and 1709/1803 hosts, as KEV listing requires remediation per vendor instructions. Prioritize systems where local code execution is plausible (user workstations, RDP-exposed or otherwise accessed servers) since ransomware operators are known to exploit this flaw post-foothold. Windows 8.1, Windows RT 8.1, and Windows Server 2012/2012 R2 are now end-of-support, so plan migration or compensating hardening for any remaining unpatched legacy hosts.

Affected
microsoft Windows 10 1507build 1507, all builds prior to the July 2018 security updates
microsoft Windows 10 1607build 1607, all builds prior to the July 2018 security updates
microsoft Windows 10 1703build 1703, all builds prior to the July 2018 security updates
microsoft Windows 10 1709build 1709, all builds prior to the July 2018 security updates
microsoft Windows 10 1803build 1803, all builds prior to the July 2018 security updates
microsoft Windows 8.1all supported versions prior to the July 2018 security updates
microsoft Windows RT 8.1all supported versions prior to the July 2018 security updates
microsoft Windows Server 1709Semi-Annual Channel 1709, prior to the July 2018 security updates
microsoft Windows Server 1803Semi-Annual Channel 1803, prior to the July 2018 security updates
microsoft Windows Server 20122012 and 2012 R2 (R2 named in the advisory description), prior to the July 2018 security updates
microsoft Windows Server 2016all builds prior to the July 2018 security updates
Estimated exposure
mass≈hundreds of millions of Windows devices at time of disclosure (Windows 10 alone ran on 700M+ devices in 2018; Server 2012/2016 were dominant server releases) — The vulnerable DXGKRNL driver ships in every Windows 8.1/RT 8.1, Windows 10 (1507-1803), and Windows Server 2012/2016 installation, a combined install base in the hundreds of millions in 2018, though exploitation requires prior local code…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory, aka "DirectX Graphics Kernel Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8400, CVE-2018-8401, CVE-2018-8406.

CISA Known Exploited Vulnerability
Affected
Microsoft DirectX Graphics Kernel (DXGKRNL)
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1703, windows 10 1709, windows 10 1803, windows 8.1, windows rt 8.1, windows server 1709, windows server 1803, windows server 2012, windows server 2016
Weakness
CWE-404
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.