EXPOSURES › CVE-2018-8406
CVE-2018-8406
CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
⌖ EXPLOITED IN THE WILD
SHAME 80/100
ransomwareexploited-in-wild
A Microsoft DirectX Graphics Kernel vulnerability allowed privilege escalation, actively exploited and linked to ransomware attacks, impacting DIB systems relying on DirectX drivers.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
PLAYERS IMPLICATED
DESCRIPTION
An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory.
AFFECTED FEDRAMP PRODUCTS · 4
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |