Vulnerability Details CVE-2018-19321
The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.21
EPSS Ranking 95.4%
CVSS Severity
CVSS v3 Score 7.8
CVSS v2 Score 7.2
Proposed Action
The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.
Ransomware Campaign
Known
Products affected by CVE-2018-19321
-
cpe:2.3:a:gigabyte:aorus_graphics_engine:1.33
-
cpe:2.3:a:gigabyte:app_center:1.05.21
-
cpe:2.3:a:gigabyte:app_center:19.0227.1
-
cpe:2.3:a:gigabyte:oc_guru_ii:2.08
-
cpe:2.3:a:gigabyte:xtreme_gaming_engine:1.22
-
cpe:2.3:a:gigabyte:xtreme_gaming_engine:1.25