CVE-2018-19323 KEV
9.8
CRITICAL · CVSS 3.1 · EPSS 7.8% (pctl 94)
Patch first
On CISA KEV — known exploited in the wild, due 2022-11-14.
Description
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes functionality to read and write Machine Specific Registers (MSRs).
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 7.83% — more likely to be exploited than 94% of all CVEs |
| On CISA KEV | yes — remediate by 2022-11-14 |
| Public exploit | none known |
| Published | 2018-12-21 |
| Last modified | 2026-08-13 |
CISA KEV
| Name | GIGABYTE Multiple Products Privilege Escalation Vulnerability |
|---|---|
| Added | 2022-10-24 |
| Due | 2022-11-14 |
| Vendor / product | GIGABYTE / Multiple Products |
| Ransomware use | known |
Affected (4)
| Vendor | Product |
|---|---|
| gigabyte | aorus graphics engine |
| gigabyte | gigabyte app center |
| gigabyte | oc guru ii |
| gigabyte | xtreme gaming engine |
References
- http://seclists.org/fulldisclosure/2018/Dec/39
- http://www.securityfocus.com/bid/106252
- https://www.gigabyte.com/Support/Security/1801
- https://www.gigabyte.com/tw/Support/Utility/Graphics-Card
- https://www.secureauth.com/labs/advisories/gigabyte-drivers-elevation-privilege-vulnerabilities
- http://seclists.org/fulldisclosure/2018/Dec/39
- http://www.securityfocus.com/bid/106252
- https://www.gigabyte.com/Support/Security/1801
- https://www.gigabyte.com/tw/Support/Utility/Graphics-Card
- https://www.secureauth.com/labs/advisories/gigabyte-drivers-elevation-privilege-vulnerabilities
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-19323
→ the Explorer · watch your stack · NVD