LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2018-8406: Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 28, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Apr 18, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2018-8406 to its Known Exploited Vulnerabilities catalog on Mar 28, 2022, with a federal patch deadline of Apr 18, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory.

CVE-2018-8406 is an elevation-of-privilege vulnerability in the Microsoft DirectX Graphics Kernel driver (DXGKRNL). When the driver improperly handles objects in memory, a local attacker who already has some access can potentially raise their privileges on the system. This matters because privilege escalation is a common step after initial access, and the vulnerability has been associated with ransomware activity. Defenders should treat it as a priority for Windows hosts that use DirectX graphics components and confirm all version and patch details against the vendor advisory.

How it works

The weakness is categorized as CWE-404 (Improper Resource Shutdown or Release). In practical terms, the DirectX Graphics Kernel driver fails to handle certain objects in memory correctly. An attacker who can run code in a less-privileged context may abuse that mishandling to influence kernel-mode state and obtain higher privileges.

Public detail on exact exploit mechanics is limited. Exploitation would typically require local code execution or the ability to interact with the vulnerable driver path; remote unauthenticated exploitation is not indicated by the given summary. Treat any claimed proof-of-concept or specific trigger as unverified until checked against Microsoft’s advisory and your own testing. The outcome of successful abuse is elevation of privilege on the affected host, which can then be used for persistence, lateral movement, or deployment of further payloads including ransomware.

Am I affected? How to find it in your systems

DXGKRNL is part of the Windows graphics stack and is present on systems that use DirectX, including many desktops, laptops, and servers with graphical or remote-display components. It is a kernel-mode driver, so exposure is local to the Windows host rather than a network service listening by default.

How to remediate

Patch first. Apply the Microsoft updates that address CVE-2018-8406 exactly as directed in the vendor advisory and CISA’s required action (“Apply updates per vendor instructions”). Validate installation via your patch-management console and by confirming the updated driver/OS build on sample hosts.

If you can't patch immediately

Compensating controls reduce but do not eliminate risk. Use them only as a bridge until the vendor update is applied.

If your data may have been exposed

Actively exploited elevation-of-privilege vulnerabilities are often chained into broader compromises and ransomware. If you have evidence of exploitation or have not yet patched, assume the host may have been used to reach credentials, files, or other systems. Follow your incident-response process: isolate affected machines, preserve forensic data, reset credentials, and hunt for persistence and lateral movement. As an additional check for personal or corporate email addresses that may appear in known breach data, you can run a free exposure scan of your email to see whether those identities have shown up in published breach corpora.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · DirectX Graphics Kernel (DXGKRNL)
WeaknessCWE-404
Added to CISA KEVMar 28, 2022
Federal patch deadlineApr 18, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities