CVE-2018-19321
Published · Updated
71Vexday Risk Score
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
ssvc Actcvss 7.8epss 3.7%
from disclosure to weapon1222 days
Published on NVDDec 21
1st PoC+1222d
CISA KEV+1403d
exploitation probability
3.7%top 11% of all CVEs
observed exploitation
yesCISA + VulnCheck
3 public exploit(s)
Action required by CISAfederal deadline: 2022-11-14
Apply updates per vendor instructions.
In short
GIGABYTE's system drivers allow any local user to read and write computer memory directly, which can be exploited to gain administrator privileges on the machine.
Technical detail
The GPCIDrv and GDrv drivers in multiple GIGABYTE applications expose arbitrary physical memory read/write primitives accessible to local users; an unprivileged attacker can leverage this to bypass kernel protections and escalate privileges to SYSTEM level.
Summary generated and translated by AI from the official description.
The full analysis of this CVE is available in Portuguese →
The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/apublic PoCs found — 3
githubgithub.com/nanabingies/Driver-RW★ 8githubgithub.com/nanabingies/CVE-2018-19321★ 2vulncheckvulncheck.com/xdb/74650e8a4a65unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://seclists.org/fulldisclosure/2018/Dec/39https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-19321https://www.gigabyte.com/Support/Security/1801https://www.secureauth.com/labs/advisories/gigabyte-drivers-elevation-privilege-vulnerabilitieshttp://www.securityfocus.com/bid/106252