ZeroHour

CVE-2018-8406

KEV ransomwaremass

Local Privilege Escalation in Microsoft DirectX Graphics Kernel (DXGKRNL) Driver

CISA: Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
3%p88
Published
()
KEV added
AI analysis

An elevation-of-privilege flaw exists in the Microsoft DirectX Graphics Kernel (DXGKRNL) driver, which improperly handles objects in memory (CWE-404). A local attacker with low privileges who can already run code on an affected machine can trigger the mishandled object handling to execute code at kernel level. Successful exploitation yields high confidentiality, integrity and availability impact — effectively full control of the host — which fits post-compromise escalation in ransomware tradecraft. Affected platforms are Windows 10 builds 1507, 1607, 1703, 1709 and 1803, and Windows Server 2016, 1709 and 1803; it is one of a family of sibling DXGKRNL EoP bugs (CVE-2018-8400, 8401, 8405, 8406). The flaw is under active exploitation: it was added to the CISA KEV on 2022-03-28 with known ransomware use, and Microsoft shipped fixes in July 2018 security updates.

What to do: Apply Microsoft's July 2018 (or any later) cumulative/security updates to Windows 10 1507–1803 and Windows Server 2016/1709/1803 — any current servicing build resolves this DXGKRNL bug. Because the CVE is KEV-listed with known ransomware use, prioritize patching unpatched legacy Windows 10/Server 2016-era hosts, especially endpoints where users run unprivileged code; as an interim mitigation, limit local code execution (application control, removing users' ability to run arbitrary binaries) and monitor for post-authentication privilege-escalation activity.

Affected
Microsoft Windows 101507, 1607, 1703, 1709, 1803
Microsoft Windows Server 2016per CPE listing, no specific build ranges given
Microsoft Windows Server 1709per CPE listing, no specific build ranges given
Microsoft Windows Server 1803per CPE listing, no specific build ranges given
Estimated exposure
massorder of 100M+ Windows 10 installations (plus enterprise Windows Server 2016/1709/1803 deployments) at time of the July 2018 fix; unknown residual exposure… — At disclosure the Windows 10 builds in scope (1507–1803) represented essentially the entire ~700M-device Windows 10 install base, and Windows Server 2016 was a mainstream enterprise release, so the population plausibly affected at patch…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory, aka "DirectX Graphics Kernel Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8400, CVE-2018-8401, CVE-2018-8405.

CISA Known Exploited Vulnerability
Affected
Microsoft DirectX Graphics Kernel (DXGKRNL)
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1703, windows 10 1709, windows 10 1803, windows server 1709, windows server 1803, windows server 2016
Weakness
CWE-404
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.