peter bassill · operator
$ cve CVE-2018-19323 JSON

CVE-2018-19323 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 7.8% (pctl 94)

Patch first

On CISA KEV — known exploited in the wild, due 2022-11-14.

Description

The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes functionality to read and write Machine Specific Registers (MSRs).

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS7.83% — more likely to be exploited than 94% of all CVEs
On CISA KEVyes — remediate by 2022-11-14
Public exploitnone known
Published2018-12-21
Last modified2026-08-13

CISA KEV

NameGIGABYTE Multiple Products Privilege Escalation Vulnerability
Added2022-10-24
Due2022-11-14
Vendor / productGIGABYTE / Multiple Products
Ransomware useknown

Affected (4)

VendorProduct
gigabyteaorus graphics engine
gigabytegigabyte app center
gigabyteoc guru ii
gigabytextreme gaming engine

References

→ the Explorer  ·  watch your stack  ·  NVD