HackerFeeds
All CVEs

CVE-2018-19323

CRITICAL9.8
CISA KEV

Published 2018-12-21 · Updated 2026-08-13 · Source cve@mitre.org

Description

The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes functionality to read and write Machine Specific Registers (MSRs).

CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA Known-Exploited Vulnerability

Product: GIGABYTEMultiple Products

Name: GIGABYTE Multiple Products Privilege Escalation Vulnerability

Date added: 2022-10-24 · Due: 2022-11-14

USED IN RANSOMWARE

Required action: Apply updates per vendor instructions.

View on NVD