Skip to content
COOEY

EXPOSURES › CVE-2018-8405

CVE-2018-8405

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-28 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2018-8405 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 ransomwareexploited-in-wildunpatchedrce

A Microsoft DirectX Graphics Kernel vulnerability allowed privilege escalation, actively exploited and linked to ransomware attacks, impacting DIB systems relying on DirectX drivers.

CVE-2018-8405 in the DirectX Graphics Kernel driver improperly handled memory objects, enabling privilege escalation. This vulnerability is actively exploited and has been linked to ransomware campaigns, posing a significant risk to DIB organizations using affected systems; immediate patching and vulnerability scanning are critical. Failure to address this could lead to compliance failures under NIST 800-171 and potential data breaches.

Shame score — The widespread exploitation and ransomware linkage demonstrate a significant failure in Microsoft's driver security, impacting a core component of many DIB systems.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory.

AFFECTED FEDRAMP PRODUCTS · 4
PRODUCTSTATUS
Azure Commercial Cloud
Microsoft
Authorized
Azure Government (includes Dynamics 365)
Microsoft
Authorized
Microsoft Office 365 GCC High
Microsoft
In Process
Office 365 Multi-Tenant & Supporting Services
Microsoft
Authorized