CVE-2018-8484
published 2018-10-10CVE-2018-8484: An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory, aka "DirectX Graphics…
PriorityP338high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
1.18%
64.3th percentile
An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory, aka "DirectX Graphics Kernel Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows Server 2019, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers.
Affected
43 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_servers | — | — |
| microsoft | windows_10_servers | — | — |
| microsoft | windows_8.1 | — | — |
| microsoft | windows_8.1 | — | — |
| microsoft | windows_rt_8.1 | — | — |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012_r2 | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_msrc7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
DirectX Graphics Kernel Elevation of Privilege Vulnerability
vendor_msrc·2018-10-09·CVSS 7.0
CVE-2018-8484 [HIGH] DirectX Graphics Kernel Elevation of Privilege Vulnerability
DirectX Graphics Kernel Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
To exploit the vulnerability, an attacker would first have to log on to the system, and then run a specially crafted application to take control over the affected system.
The security update addresses the vulnerability by correcting how DXGKRNL handles objects in memory.
Microsoft Graphics Component: Microsoft Graphics Component
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:
GHSA
GHSA-4mp3-pj6p-v498: An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory, aka "DirectX Gr
ghsa_unreviewed·2022-05-13
CVE-2018-8484 [HIGH] CWE-404 GHSA-4mp3-pj6p-v498: An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory, aka "DirectX Gr
An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory, aka "DirectX Graphics Kernel Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows Server 2019, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers.
No detection rules found.
No public exploits indexed.
arXiv
Cyber Situation Awareness Monitoring and Proactive Response for Enterprises on the Cloud
arxiv_fulltext·2020-09-03
Cyber Situation Awareness Monitoring and Proactive Response for Enterprises on the Cloud
Cyber Situation Awareness Monitoring and Proactive Response for Enterprises on the Cloud
Hootan Alavizadeh1, Hooman Alavizadeh2 and Julian Jang-Jaccard2
1 Computer Engineering Department,
Imam Reza International University, Mashhah, Iran.
Email: [email protected]
2 School of Natural and Computational Sciences,
Massey University, Auckland, New Zealand.
Email: \h.alavizadeh,J.Jang-jaccard\@massey.ac.nz
## Abstract
The cloud model allows many enterprises able to outsource computing resources at an affordable price without having to commit the expense upfront. Although the cloud providers are responsible for the security of the cloud, there are still many security concerns due to inherently complex model the cloud providers operate on (e.g.,multi-tenancy). In addition, the ente
Talos
Microsoft Patch Tuesday — October 18: Vulnerability disclosures and Snort coverage
blogs_talos·2018-10-09·CVSS 7.5
[HIGH] Microsoft Patch Tuesday — October 18: Vulnerability disclosures and Snort coverage
Microsoft released its monthly security update today, disclosing a variety of vulnerabilities in several of its products. The latest Patch Tuesday covers 49 vulnerabilities, 12 of which are rated "critical," 34 that are rated "important,” two that are considered to have “moderate” severity and one that’s rated as “low.”
The advisories cover bugs in the Chakra scripting engine, the Microsoft Edge internet browser and the Microsoft Office suite of products, among other software.
This update also includes a critical advisory that covers updates to the Microsoft Office suite of products.
Please visit the SNORTⓇ blog here if you would like to know more about the coverage we have for these vulnerabilities.
Critical vulnerabilities
Microsoft has disclosed 12 critical vulnerabilities this mont
Talos
Microsoft Patch Tuesday — October 18: Vulnerability disclosures and Snort coverage
blogs_talos·2018-10-09·CVSS 7.5
[HIGH] Microsoft Patch Tuesday — October 18: Vulnerability disclosures and Snort coverage
## Microsoft Patch Tuesday — October 18: Vulnerability disclosures and Snort coverage
Microsoft released its monthly security update today, disclosing a variety of vulnerabilities in several of its products. The latest Patch Tuesday covers 49 vulnerabilities, 12 of which are rated "critical," 34 that are rated "important,” two that are considered to have “moderate” severity and one that’s rated as “low.”
The advisories cover bugs in the Chakra scripting engine, the Microsoft Edge internet browser and the Microsoft Office suite of products, among other software.
This update also includes a critical advisory that covers updates to the Microsoft Office suite of products .
Please visit the SNORTⓇ blog here if you would like to know more about the coverage we have for these vulnerabilities.
http://www.securityfocus.com/bid/105500http://www.securitytracker.com/id/1041823https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8484http://www.securityfocus.com/bid/105500http://www.securitytracker.com/id/1041823https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8484
2018-10-10
Published