SB2018100921 - Multiple vulnerabilities in DirectX for Microsoft Windows
Published: October 9, 2018
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Information disclosure (CVE-ID: CVE-2018-8486)
The vulnerability allows a remote authenticated attacker to obtain potentially sensitive information.
The vulnerability exists due to improper handling of objects in memory by DirectX component. A remote attacker can run a specially crafted application and obtain information to further compromise the user’s system.
2) Privilege escalation (CVE-ID: CVE-2018-8484)
The vulnerability allows a local authenticated attacker to gain elevated privileges.
The vulnerability exists due to improper handling of objects in memory by the DirectX Graphics Kernel (DXGKRNL) driver. A local attacker can run a specially crafted application and gain SYSTEM privileges to conduct further attacks.
Remediation
Install update from vendor's website.