CVE-2018-19321
high · 7.8Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply updates per vendor instructions.
Added 2022-10-24Remediation due 2022-11-14
The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.
7.8
CVSS
3.7%
EPSS (exploit prob.)
89th
EPSS percentile
2018-12-21
Published
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| gigabyte | aorus_graphics_engine | < 1.57 |
| gigabyte | app_center | < 19.0422.1 |
| gigabyte | oc_guru_ii | 2.08 |
| gigabyte | xtreme_gaming_engine | < 1.26 |
Check a specific version with /api/v1/cve/match.
References
- http://seclists.org/fulldisclosure/2018/Dec/39
- http://www.securityfocus.com/bid/106252
- https://www.gigabyte.com/Support/Security/1801
- https://www.secureauth.com/labs/advisories/gigabyte-drivers-elevation-privilege-vulnerabilities
- http://seclists.org/fulldisclosure/2018/Dec/39
- http://www.securityfocus.com/bid/106252
- https://www.gigabyte.com/Support/Security/1801
- https://www.secureauth.com/labs/advisories/gigabyte-drivers-elevation-privilege-vulnerabilities
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-19321
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2018-19321