Microsoft DirectX Information Disclosure Vulnerability

By GIXnews

A vulnerability in the DirectX component of Microsoft Windows could allow a local attacker to access sensitive information on a targeted system.

The vulnerability is due to improper memory operations that are performed by the affected software when processing memory objects. An attacker could exploit this vulnerability by accessing the system and executing an application that submits malicious input to the affected software. A successful exploit could allow the attacker to access sensitive information, which could be used to conduct additional attacks.

Microsoft confirmed the vulnerability and released software updates.

Security Impact Rating: Medium

CVE: CVE-2018-8486

Source:: Cisco Multivendor Vulnerability Alerts