← All CVEs

CVE-2018-19321

high · 7.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2022-10-24Remediation due 2022-11-14

The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.

7.8
CVSS
3.7%
EPSS (exploit prob.)
89th
EPSS percentile
2018-12-21
Published

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

VendorProductAffected versions
gigabyteaorus_graphics_engine< 1.57
gigabyteapp_center< 19.0422.1
gigabyteoc_guru_ii2.08
gigabytextreme_gaming_engine< 1.26

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2018-19321