Vulnerability record · CVE-2022-37954 · published 13 September 2022
CVE-2022-37954: Microsoft Windows DirectX Graphics Kernel elevation of privilege
Microsoft · Windows 10
CVE-2022-37954 is an elevation of privilege flaw in the DirectX Graphics Kernel component of Microsoft Windows 10, Windows 11, Windows Server 2019 and Windows Server 2022. The record gives no root-cause detail beyond the component name, so the exact defect is unknown, but successful abuse would let a local user gain higher privileges on the host.
Description
DirectX Graphics Kernel Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityLocal privilege escalation with high confidentiality, integrity and availability impact and a very high EPSS score, though no confirmed exploitation or KEV listing.
What it is
CVE-2022-37954 is an elevation of privilege flaw in the DirectX Graphics Kernel component of Microsoft Windows 10, Windows 11, Windows Server 2019 and Windows Server 2022. The record gives no root-cause detail beyond the component name, so the exact defect is unknown, but successful abuse would let a local user gain higher privileges on the host.
Impact
An attacker who already has code running on the machine can elevate to a higher-privileged context, potentially SYSTEM, giving full control of the affected host.
Attack surface
The CVSS vector is local (AV:L) with low privileges required (PR:L) and no user interaction (UI:N), so the flaw is reached by running code on the target system rather than over the network. No remote or unauthenticated path is described.
Exploitation
Not listed in CISA KEV and no reference carries an exploit tag, so there is no confirmed in-the-wild exploitation in this record. EPSS is high at 0.449 (98.7th percentile), indicating elevated predicted likelihood of exploitation activity.
What to do
- Apply the Microsoft security update for CVE-2022-37954 on all affected Windows 10, Windows 11, Windows Server 2019 and Windows Server 2022 systems.
- Prioritize patching on multi-user hosts, terminal servers and systems where untrusted users can execute code.
- Restrict local logon and code execution rights to reduce the pool of users who can trigger the flaw.
- Monitor for privilege escalation attempts against the DirectX Graphics Kernel and investigate unexpected SYSTEM-level process creation.
Detection
- Alert on processes gaining SYSTEM or other elevated tokens from non-administrative parent processes.
- Monitor for unusual access or load activity involving DirectX and graphics kernel drivers by low-privileged users.
- Correlate local privilege escalation indicators with post-exploitation behavior such as new services, scheduled tasks or credential access.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-37954 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-37954), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.