All CVEs View on NVD
CVE-2018-19321
HIGH7.8
CISA KEV
Published 2018-12-21 · Updated 2026-08-13 · Source cve@mitre.org
Description
The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.
CVSS vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA Known-Exploited Vulnerability
Product: GIGABYTE — Multiple Products
Name: GIGABYTE Multiple Products Privilege Escalation Vulnerability
Date added: 2022-10-24 · Due: 2022-11-14
USED IN RANSOMWARE
Required action: Apply updates per vendor instructions.
References
- http://seclists.org/fulldisclosure/2018/Dec/39
- http://www.securityfocus.com/bid/106252
- https://www.gigabyte.com/Support/Security/1801
- https://www.secureauth.com/labs/advisories/gigabyte-drivers-elevation-privilege-vulnerabilities
- http://seclists.org/fulldisclosure/2018/Dec/39
- http://www.securityfocus.com/bid/106252
- https://www.gigabyte.com/Support/Security/1801
- https://www.secureauth.com/labs/advisories/gigabyte-drivers-elevation-privilege-vulnerabilities

