Apply updates per vendor instructions.
Evidence dossier
CVE-2018-8406
CVE-2018-8406
gen-409cbd0cNormalized restatement
An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory, aka "DirectX Graphics Kernel Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8400, CVE-2018-8401, CVE-2018-8405.
- State
- PUBLISHED
- Published
- Aug 15, 2018
- Updated
- Oct 21, 2025
- Evidence coverage
- 85%
2026-07-18 · v2026.06.15 · percentile 87.7%
Distinct CVSS assessments remain side by side; none are averaged.
Source comparison
Who said what
An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory, aka "DirectX Graphics Kernel Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8400, CVE-2018-8401, CVE-2018-8405.
Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability
Probability 0.034440000000; percentile 0.876700000000
Applicability
Cited product scope
Grouped from 1 configuration nodes in this exact generation. Visual grouping does not establish asset exposure or common root cause.
Identity source boundaries
- cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
11 scope groups
[{"status": "affected", "version": "32-bit Systems"}, {"status": "affected", "version": "Version 1607 for 32-bit Systems"}, {"status": "affected", "version": "Version 1607 for x64-based Systems"}, {"status": "affected", "version": "Version 1703 for 32-bit Systems"}, {"status": "affected", "version": "Version 1703 for x64-based Systems"}, {"status": "affected", "version": "Version 1709 for 32-bit Systems"}, {"status": "affected", "version": "Version 1709 for x64-based Systems"}, {"status": "affected", "version": "Version 1803 for 32-bit Systems"}, {"status": "affected", "version": "Version 1803 for x64-based Systems"}, {"status": "affected", "version": "x64-based Systems"}][{"status": "affected", "version": "version 1709 (Server Core Installation)"}, {"status": "affected", "version": "version 1803 (Server Core Installation)"}][{"status": "affected", "version": "(Server Core installation)"}]Version not applicableCanonical identity product-9851bd571b8ab08bca589cd73710badfef557d036f0fb7707f694f1c9f597cb4linked exactInspect 2 returned assertions
cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:x86:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
28a7fee9-b473-48a0-b0ed-a5cc1e44194c
cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:x64:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a045ac0a-471e-444c-b3b0-4cabc23e8cfb
Version not applicableCanonical identity product-740fec3e9838b5eabe76ebe27e4d0d7a4cb2e0ef7e13923300d3d0b51e3fce1clinked exactInspect 2 returned assertions
cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:x86:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0a1bc97a-263e-4291-8aef-02ee4e6031e9
cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:x64:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5e491e46-1917-41fe-8f9a-bb0bddeb42c3
Version not applicableCanonical identity product-2f3550a8fd2528ab6e756c5ea638f5f3dc368adee47ca6f01d64918c0b9eb2a5linked exactInspect 2 returned assertions
cpe:2.3:o:microsoft:windows_10_1703:-:*:*:*:*:*:x86:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8733bf37-7bf2-409d-9452-da8a92da1124
cpe:2.3:o:microsoft:windows_10_1703:-:*:*:*:*:*:x64:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b98db3ff-cc3b-4e9f-a9cc-ec4c89af3b31
Version not applicableCanonical identity product-d059dbfcd39652adfca6d48669484008cb5d4a8b33116c81ee002cd9101904aflinked exactInspect 2 returned assertions
cpe:2.3:o:microsoft:windows_10_1709:-:*:*:*:*:*:x86:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d76003fb-ee99-4d8e-b6a0-b13c2041e5a0
cpe:2.3:o:microsoft:windows_10_1709:-:*:*:*:*:*:x64:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
469f95d3-abbb-4f1a-a000-be0f6bd60ff6
Version not applicableCanonical identity product-5e821ea3746af154a469c180e78b9f4d663edf21461517987eed76740c7910c1linked exactInspect 2 returned assertions
cpe:2.3:o:microsoft:windows_10_1803:-:*:*:*:*:*:x64:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d82f8af7-ed01-4649-849e-f248f0e02384
cpe:2.3:o:microsoft:windows_10_1803:-:*:*:*:*:*:x86:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c1cfb53b-b17b-47bd-bac1-c6c5d168ffb6
Version not applicableCanonical identity product-ff9203e1d48a9425faa287000b301451cdbb2a9defda0e208f1ce06fd168da7dlinked exactInspect 1 returned assertions
cpe:2.3:o:microsoft:windows_server_1709:-:*:*:*:*:*:x64:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9efb4440-2b6b-486f-94d4-7d9c80301e51
Version not applicableCanonical identity product-a74a0925fd770075058392e2bb7a5408e96a296354955527de213995d5070448linked exactInspect 1 returned assertions
cpe:2.3:o:microsoft:windows_server_1803:-:*:*:*:*:*:x64:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 11
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
fd3218d1-be39-4ceb-a88f-e715b722862b
Version not applicableCanonical identity product-02e254d111ce604757a15650ef469f4f8365d6247da82ce3ac2695c3cfc7dc5flinked exactInspect 1 returned assertions
cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*- Official link
- linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 12
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
041ff8ba-0b12-4a1f-b4bf-9c4f33b7c1e7
Assessments
CVSS by origin
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HAV:L/AC:L/Au:N/C:C/I:C/A:CCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HLimitations and unknowns
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; unresolved scope remains unknown.
- NVD-carried upstream facts remain derivative and are not independent corroboration.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Factor D remains unknown because WC-03 has not converted canonical CPE mappings into generation-bound mapping obligations; canonical identity alone does not score applicability.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.