CVE-2018-8405 is an elevation of privilege vulnerability in the DirectX Graphics Kernel (DXGKRNL) driver, affecting various Windows operating systems including Windows 8.1, 10, and Server versions. With a CVSS score of 7.8 (High), it allows a local attacker with low privileges to achieve high impact on confidentiality, integrity, and availability. This vulnerability is actively exploited, including in known ransomware campaigns, despite no public exploit code being readily available in Metasploit or ExploitDB. Community discussion and media coverage indicate significant attention to this flaw.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:x64:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:x86:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:x64:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:x86:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1703:-:*:*:*:*:*:x64:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.