Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2018-19323

The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes functionality to read and write Machine Specific Registers (MSRs).
Exploit prediction scoring system (EPSS) score
EPSS Score 0.231
EPSS Ranking 95.7%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 9.0
Proposed Action
The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.
Ransomware Campaign
Known
Products affected by CVE-2018-19323


Contact Us

Shodan ® - All rights reserved