ZeroHour

CVE-2018-19320

KEV ransomware PoC ×2mass

Ring0 Memcpy Flaw in GIGABYTE GDrv Driver Enables Local Privilege Escalation

CISA: GIGABYTE Multiple Products Unspecified Vulnerability

CVSS 3.1
7.8 high
EPSS
4%p89
Published
()
KEV added
AI analysis

CVE-2018-19320 is a local privilege-escalation flaw in the GDrv (gdrv.sys) low-level Windows kernel driver shipped with GIGABYTE APP Center (v1.05.21 and earlier), AORUS GRAPHICS ENGINE (before 1.57), XTREME GAMING ENGINE (before 1.26), and OC GURU II (v2.08). The driver exposes an unchecked ring0 memcpy-like routine, so a low-privileged local process can have it copy attacker-controlled data into protected kernel memory. An attacker who exploits this gains complete control of the affected system at ring 0, enabling kernel-level code execution and the ability to disable security software, which ransomware operators such as RobbinHood and BlackByte have done by leveraging the vulnerable GIGABYTE driver. Any Windows system running one of the affected GIGABYTE utilities, or where the gdrv.sys driver those utilities install remains present, is exposed. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-10-24 with known ransomware use and is being actively exploited; EPSS estimates a 3.6% probability of exploitation within 30 days (89th percentile).

What to do: Apply vendor updates per CISA's required action: upgrade to AORUS GRAPHICS ENGINE 1.57 or later, XTREME GAMING ENGINE 1.26 or later, and current APP Center and OC GURU II releases, or uninstall the utilities entirely. Hunt endpoints for the gdrv.sys driver in the System32 drivers folder, since it can persist after the utility is removed, and prioritize patching systems where unprivileged users can invoke it, as ransomware operators actively load or exploit this driver to gain ring0 access and kill security software.

Affected
GIGABYTE APP Centerv1.05.21 and earlier
GIGABYTE AORUS GRAPHICS ENGINEbefore 1.57
GIGABYTE XTREME GAMING ENGINEbefore 1.26
GIGABYTE OC GURU IIv2.08
Estimated exposure
mass≈1,000,000+ systems (bundled utilities from a top-tier motherboard/GPU vendor; no published install counts) — No install counts are published, but GIGABYTE is among the world's largest motherboard and graphics-card vendors and these utilities bundle with its boards and cards, so even a small fraction of that installed base running APP Center,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes ring0 memcpy-like functionality that could allow a local attacker to take complete control of the affected system.

CISA Known Exploited Vulnerability
Affected
GIGABYTE Multiple Products
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
gigabyte
Products
aorus graphics engine, app center, oc guru ii, xtreme gaming engine
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news