CVE-2018-8406
KEV ransomwaremassLocal Privilege Escalation in Microsoft DirectX Graphics Kernel (DXGKRNL) Driver
CISA: Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability
An elevation-of-privilege flaw exists in the Microsoft DirectX Graphics Kernel (DXGKRNL) driver, which improperly handles objects in memory (CWE-404). A local attacker with low privileges who can already run code on an affected machine can trigger the mishandled object handling to execute code at kernel level. Successful exploitation yields high confidentiality, integrity and availability impact — effectively full control of the host — which fits post-compromise escalation in ransomware tradecraft. Affected platforms are Windows 10 builds 1507, 1607, 1703, 1709 and 1803, and Windows Server 2016, 1709 and 1803; it is one of a family of sibling DXGKRNL EoP bugs (CVE-2018-8400, 8401, 8405, 8406). The flaw is under active exploitation: it was added to the CISA KEV on 2022-03-28 with known ransomware use, and Microsoft shipped fixes in July 2018 security updates.
What to do: Apply Microsoft's July 2018 (or any later) cumulative/security updates to Windows 10 1507–1803 and Windows Server 2016/1709/1803 — any current servicing build resolves this DXGKRNL bug. Because the CVE is KEV-listed with known ransomware use, prioritize patching unpatched legacy Windows 10/Server 2016-era hosts, especially endpoints where users run unprivileged code; as an interim mitigation, limit local code execution (application control, removing users' ability to run arbitrary binaries) and monitor for post-authentication privilege-escalation activity.
| Microsoft Windows 10 | 1507, 1607, 1703, 1709, 1803 |
| Microsoft Windows Server 2016 | per CPE listing, no specific build ranges given |
| Microsoft Windows Server 1709 | per CPE listing, no specific build ranges given |
| Microsoft Windows Server 1803 | per CPE listing, no specific build ranges given |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory, aka "DirectX Graphics Kernel Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8400, CVE-2018-8401, CVE-2018-8405.
- Affected
- Microsoft DirectX Graphics Kernel (DXGKRNL)
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1703, windows 10 1709, windows 10 1803, windows server 1709, windows server 1803, windows server 2016
- Weakness
- CWE-404
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.