CVE-2018-19320
KEV ransomware PoC ×2massRing0 Memcpy Flaw in GIGABYTE GDrv Driver Enables Local Privilege Escalation
CISA: GIGABYTE Multiple Products Unspecified Vulnerability
CVE-2018-19320 is a local privilege-escalation flaw in the GDrv (gdrv.sys) low-level Windows kernel driver shipped with GIGABYTE APP Center (v1.05.21 and earlier), AORUS GRAPHICS ENGINE (before 1.57), XTREME GAMING ENGINE (before 1.26), and OC GURU II (v2.08). The driver exposes an unchecked ring0 memcpy-like routine, so a low-privileged local process can have it copy attacker-controlled data into protected kernel memory. An attacker who exploits this gains complete control of the affected system at ring 0, enabling kernel-level code execution and the ability to disable security software, which ransomware operators such as RobbinHood and BlackByte have done by leveraging the vulnerable GIGABYTE driver. Any Windows system running one of the affected GIGABYTE utilities, or where the gdrv.sys driver those utilities install remains present, is exposed. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-10-24 with known ransomware use and is being actively exploited; EPSS estimates a 3.6% probability of exploitation within 30 days (89th percentile).
What to do: Apply vendor updates per CISA's required action: upgrade to AORUS GRAPHICS ENGINE 1.57 or later, XTREME GAMING ENGINE 1.26 or later, and current APP Center and OC GURU II releases, or uninstall the utilities entirely. Hunt endpoints for the gdrv.sys driver in the System32 drivers folder, since it can persist after the utility is removed, and prioritize patching systems where unprivileged users can invoke it, as ransomware operators actively load or exploit this driver to gain ring0 access and kill security software.
| GIGABYTE APP Center | v1.05.21 and earlier |
| GIGABYTE AORUS GRAPHICS ENGINE | before 1.57 |
| GIGABYTE XTREME GAMING ENGINE | before 1.26 |
| GIGABYTE OC GURU II | v2.08 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes ring0 memcpy-like functionality that could allow a local attacker to take complete control of the affected system.
- Affected
- GIGABYTE Multiple Products
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- gigabyte
- Products
- aorus graphics engine, app center, oc guru ii, xtreme gaming engine
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H