⚠ Exploited in the wild
Exploitation observed in the wild. Not yet on CISA KEV.

CVE-2018-8638Sensitive Information Exposure in Microsoft Windows 10

5 documents5 sources
Severity
5.5MEDIUMNVD
EPSS
1.2%
top 21.01%
CISA KEV
Not in KEV
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedDec 12
Latest updateMay 13

Description

An information disclosure vulnerability exists when DirectX improperly handles objects in memory, aka "DirectX Information Disclosure Vulnerability." This affects Windows 10, Windows Server 2019.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages7 packages

CVEListV5microsoft/windows_server_2019(Server Core installation)
CVEListV5microsoft/windows_10Version 1809 for 32-bit Systems, Version 1809 for ARM64-based Systems, Version 1809 for x64-based Systems+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-h5v6-7crj-9x7q: An information disclosure vulnerability exists when DirectX improperly handles objects in memory, aka "DirectX Information Disclosure Vulnerability2022-05-13
VulnCheck
Microsoft Windows DirectX Information Disclosure Vulnerability2018

📋Vendor Advisories

1
Microsoft
DirectX Information Disclosure Vulnerability2018-12-11

🕵️Threat Intelligence

1
Tenable
Daisy Chaining: How Vulnerabilities Can Be Greater Than the Sum of Their Parts2021-01-21
CVE-2018-8638 — Sensitive Information Exposure | cvebase