ZeroHour

CVE-2018-19321

KEV ransomware PoC ×2large

Arbitrary Memory Access in GIGABYTE GPCIDrv/GDrv Drivers Enables Local Priv Escalation

CISA: GIGABYTE Multiple Products Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
4%p89
Published
()
KEV added
AI analysis

The GPCIDrv and GDrv low-level kernel drivers bundled with several GIGABYTE utilities expose functionality that lets a process read and write arbitrary physical memory. A local attacker with limited privileges can invoke this exposed functionality to modify kernel memory and elevate privileges on the Windows host. Successful exploitation grants the attacker higher privileges, typically system/administrator-level access, which is useful both as a standalone privilege-escalation step and as an enabler for post-exploitation activity. Users running GIGABYTE APP Center v1.05.21 or earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, or OC GURU II v2.08 are affected. The flaw is actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-10-24 with known ransomware use, and public proof-of-concept code has been available since December 2018.

What to do: Apply updates per vendor instructions: upgrade AORUS GRAPHICS ENGINE to 1.57 or later, XTREME GAMING ENGINE to 1.26 or later, and replace APP Center (v1.05.21 and earlier) and OC GURU II (v2.08) with updated releases. On systems where these GIGABYTE utilities are not needed, uninstalling them or removing the GPCIDrv/GDrv drivers eliminates the exposure; inventory Windows endpoints for these drivers, prioritizing endpoints exposed to ransomware.

Affected
GIGABYTE APP Centerv1.05.21 and earlier
GIGABYTE AORUS GRAPHICS ENGINEbefore 1.57
GIGABYTE XTREME GAMING ENGINEbefore 1.26
GIGABYTE OC GURU IIv2.08
Estimated exposure
largelikely hundreds of thousands of Windows systems (GIGABYTE is among the largest motherboard/GPU vendors and these utilities are commonly installed on its boards… — GIGABYTE ships millions of motherboards and GPUs and bundles these utilities with its mainstream products, so the vulnerable GPCIDrv/GDrv drivers are plausibly present on hundreds of thousands of endpoints, though exact install counts are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.

CISA Known Exploited Vulnerability
Affected
GIGABYTE Multiple Products
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
gigabyte
Products
aorus graphics engine, app center, oc guru ii, xtreme gaming engine
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news