CVE-2018-19321
KEV ransomware PoC ×2largeArbitrary Memory Access in GIGABYTE GPCIDrv/GDrv Drivers Enables Local Priv Escalation
CISA: GIGABYTE Multiple Products Privilege Escalation Vulnerability
The GPCIDrv and GDrv low-level kernel drivers bundled with several GIGABYTE utilities expose functionality that lets a process read and write arbitrary physical memory. A local attacker with limited privileges can invoke this exposed functionality to modify kernel memory and elevate privileges on the Windows host. Successful exploitation grants the attacker higher privileges, typically system/administrator-level access, which is useful both as a standalone privilege-escalation step and as an enabler for post-exploitation activity. Users running GIGABYTE APP Center v1.05.21 or earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, or OC GURU II v2.08 are affected. The flaw is actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-10-24 with known ransomware use, and public proof-of-concept code has been available since December 2018.
What to do: Apply updates per vendor instructions: upgrade AORUS GRAPHICS ENGINE to 1.57 or later, XTREME GAMING ENGINE to 1.26 or later, and replace APP Center (v1.05.21 and earlier) and OC GURU II (v2.08) with updated releases. On systems where these GIGABYTE utilities are not needed, uninstalling them or removing the GPCIDrv/GDrv drivers eliminates the exposure; inventory Windows endpoints for these drivers, prioritizing endpoints exposed to ransomware.
| GIGABYTE APP Center | v1.05.21 and earlier |
| GIGABYTE AORUS GRAPHICS ENGINE | before 1.57 |
| GIGABYTE XTREME GAMING ENGINE | before 1.26 |
| GIGABYTE OC GURU II | v2.08 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.
- Affected
- GIGABYTE Multiple Products
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- gigabyte
- Products
- aorus graphics engine, app center, oc guru ii, xtreme gaming engine
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H