CVE-2018-8405
KEV ransomwaremassLocal Privilege Escalation in Microsoft DirectX Graphics Kernel (DXGKRNL)
CISA: Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability
Microsoft's DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory, allowing a local attacker who can already execute code on a target machine to elevate privileges to kernel/SYSTEM level (CVSS 7.8, CWE-404). It is triggered by running a specially crafted local application against the vulnerable driver on affected Windows clients and servers; no remote or unauthenticated access is required. Successful exploitation yields full system compromise (confidentiality, integrity, and availability impact at the highest privilege level), and ransomware operators are known to chain such local privilege escalations onto an initial foothold. Affected products are Windows 8.1, Windows RT 8.1, Windows 10 builds 1507 through 1803, and Windows Server 2012, 2012 R2, 2016, and the Server 1709/1803 Semi-Annual Channel releases. The flaw was fixed in Microsoft's July 2018 security updates, but it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-28 with known ransomware use, confirming exploitation in the wild against unpatched systems.
What to do: Verify the July 2018 (or later) cumulative update or monthly rollup is installed on all Windows 8.1/RT 8.1, Windows 10 1507-1803, Windows Server 2012/2012 R2, 2016, and 1709/1803 hosts, as KEV listing requires remediation per vendor instructions. Prioritize systems where local code execution is plausible (user workstations, RDP-exposed or otherwise accessed servers) since ransomware operators are known to exploit this flaw post-foothold. Windows 8.1, Windows RT 8.1, and Windows Server 2012/2012 R2 are now end-of-support, so plan migration or compensating hardening for any remaining unpatched legacy hosts.
| microsoft Windows 10 1507 | build 1507, all builds prior to the July 2018 security updates |
| microsoft Windows 10 1607 | build 1607, all builds prior to the July 2018 security updates |
| microsoft Windows 10 1703 | build 1703, all builds prior to the July 2018 security updates |
| microsoft Windows 10 1709 | build 1709, all builds prior to the July 2018 security updates |
| microsoft Windows 10 1803 | build 1803, all builds prior to the July 2018 security updates |
| microsoft Windows 8.1 | all supported versions prior to the July 2018 security updates |
| microsoft Windows RT 8.1 | all supported versions prior to the July 2018 security updates |
| microsoft Windows Server 1709 | Semi-Annual Channel 1709, prior to the July 2018 security updates |
| microsoft Windows Server 1803 | Semi-Annual Channel 1803, prior to the July 2018 security updates |
| microsoft Windows Server 2012 | 2012 and 2012 R2 (R2 named in the advisory description), prior to the July 2018 security updates |
| microsoft Windows Server 2016 | all builds prior to the July 2018 security updates |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory, aka "DirectX Graphics Kernel Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8400, CVE-2018-8401, CVE-2018-8406.
- Affected
- Microsoft DirectX Graphics Kernel (DXGKRNL)
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1703, windows 10 1709, windows 10 1803, windows 8.1, windows rt 8.1, windows server 1709, windows server 1803, windows server 2012, windows server 2016
- Weakness
- CWE-404
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.