CVE-2018-19321highunder attackransomware

CVE-2018-19321

Published · Updated

71Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 7.8epss 3.7%
from disclosure to weapon1222 days
Published on NVDDec 21
1st PoC+1222d
CISA KEV+1403d
exploitation probability
3.7%top 11% of all CVEs
observed exploitation
yesCISA + VulnCheck
3 public exploit(s)
Action required by CISAfederal deadline: 2022-11-14

Apply updates per vendor instructions.

In short

GIGABYTE's system drivers allow any local user to read and write computer memory directly, which can be exploited to gain administrator privileges on the machine.

Technical detail

The GPCIDrv and GDrv drivers in multiple GIGABYTE applications expose arbitrary physical memory read/write primitives accessible to local users; an unprivileged attacker can leverage this to bypass kernel protections and escalate privileges to SYSTEM level.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.