---
cve: "CVE-2018-8405"
severity: "HIGH"
cvss: 7.8
epss: "3.4%"
vendor: "Microsoft"
kev: true
exploited: true
published: "2018-08-15 17:29:10"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-08T08:47:23+02:00"
---

# CVE-2018-8405

> 7.8 HIGH · ⚠️ CISA KEV (1625 Tage) · 🔓 Exploited

## Beschreibung

An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory, aka "DirectX Graphics Kernel Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8400, CVE-2018-8401, CVE-2018-8406.

## CVSS-Vektor

```
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Lokal | good |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Referenzen

- <http://www.securityfocus.com/bid/105011>
- <http://www.securitytracker.com/id/1041461>
- <https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8405>
- <https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-8405>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2018-8405) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
