CVE-2018-19323
critical · 9.8Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply updates per vendor instructions.
Added 2022-10-24Remediation due 2022-11-14
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes functionality to read and write Machine Specific Registers (MSRs).
9.8
CVSS
7.8%
EPSS (exploit prob.)
94th
EPSS percentile
2018-12-21
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| gigabyte | aorus_graphics_engine | < 1.57 |
| gigabyte | gigabyte_app_center | <= 1.05.21 |
| gigabyte | oc_guru_ii | 2.08 |
| gigabyte | xtreme_gaming_engine | < 1.26 |
Check a specific version with /api/v1/cve/match.
References
- http://seclists.org/fulldisclosure/2018/Dec/39
- http://www.securityfocus.com/bid/106252
- https://www.gigabyte.com/Support/Security/1801
- https://www.gigabyte.com/tw/Support/Utility/Graphics-Card
- https://www.secureauth.com/labs/advisories/gigabyte-drivers-elevation-privilege-vulnerabilities
- http://seclists.org/fulldisclosure/2018/Dec/39
- http://www.securityfocus.com/bid/106252
- https://www.gigabyte.com/Support/Security/1801
- https://www.gigabyte.com/tw/Support/Utility/Graphics-Card
- https://www.secureauth.com/labs/advisories/gigabyte-drivers-elevation-privilege-vulnerabilities
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-19323
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2018-19323