CVE-2018-8638 is an information disclosure vulnerability in DirectX that affects Windows 10 and Windows Server 2019. This medium-severity flaw (CVSS 5.5) allows a local attacker with low privileges to gain access to sensitive information due to improper memory handling. While there is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed on CISA's KEV catalog, it has received some community and media attention, including a mention in BleepingComputer regarding Microsoft's December 2018 Patch Tuesday. There is no indication of active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1809CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.