login
quiescence.eu
Saltar al contenido

CVE-2018-19323

GIGABYTE Multiple Products Privilege Escalation Vulnerability

n/a
CVSS
8.5%
EPSS (exploit prob.)
94.5%
EPSS percentile
Yes
Actively exploited
Yes
Ransomware use
2022-10-24
Added

Summary

The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.

Affected software

Vendor: GIGABYTE  ·  Product: Multiple Products

What to do

This vulnerability appears in CISA's Known Exploited Vulnerabilities catalog, meaning it is being exploited in the wild. Prioritize patching affected systems and verify exposure across your estate.

Related vulnerabilities in GIGABYTE

CVENameEPSSExploited
CVE-2018-19321 GIGABYTE Multiple Products Privilege Escalation Vulnerability 3.7% Yes
CVE-2018-19320 GIGABYTE Multiple Products Unspecified Vulnerability 3.6% Yes
CVE-2018-19322 GIGABYTE Multiple Products Code Execution Vulnerability 1.9% Yes

Is your domain exposed?

Run a free, instant security report for any domain — exposure score, email auth, TLS and breach metadata.

Get your free report

All information is aggregated from public sources for awareness only and does not constitute an accusation or a security assessment. No personal data or credentials are published.