peter bassill · operator
$ cve CVE-2018-19321 JSON

CVE-2018-19321 KEV

7.8
HIGH · CVSS 3.1 · EPSS 3.7% (pctl 89)

Patch first

On CISA KEV — known exploited in the wild, due 2022-11-14.

Description

The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.

Scoring

CVSS7.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS3.67% — more likely to be exploited than 89% of all CVEs
On CISA KEVyes — remediate by 2022-11-14
Public exploitnone known
Published2018-12-21
Last modified2026-08-13

CISA KEV

NameGIGABYTE Multiple Products Privilege Escalation Vulnerability
Added2022-10-24
Due2022-11-14
Vendor / productGIGABYTE / Multiple Products
Ransomware useknown

Affected (4)

VendorProduct
gigabyteaorus graphics engine
gigabyteapp center
gigabyteoc guru ii
gigabytextreme gaming engine

References

→ the Explorer  ·  watch your stack  ·  NVD