CVE-2018-19322
KEV ransomware PoC ×2massElevated-privilege code execution via GIGABYTE GPCIDrv/GDrv kernel drivers
CISA: GIGABYTE Multiple Products Code Execution Vulnerability
The GPCIDrv and GDrv low-level kernel drivers bundled with GIGABYTE APP Center (v1.05.21 and earlier), AORUS GRAPHICS ENGINE (before 1.57), XTREME GAMING ENGINE (before 1.26) and OC GURU II (v2.08) expose functionality that lets user-mode code read and write system IO ports. Any local, unprivileged process on a Windows host where the driver is loaded can invoke this exposed interface, and the arbitrary IO port read/write primitive can be leveraged in several ways to ultimately run code with elevated privileges — a local privilege escalation (CVSS 3.1 score 7.8, local attack vector, high impact). Affected users are owners of GIGABYTE motherboards or graphics cards who installed any of the four listed utilities, with the important caveat that the low-level drivers can remain installed and loaded even after the utility itself is uninstalled. Exploitation is confirmed: CISA added the flaw to its KEV catalog on 2022-10-24 with known ransomware use, and reporting at the time noted hackers actively exploiting it (alongside the Cisco AnyConnect flaw) in ransomware campaigns.
What to do: Apply updates per vendor instructions: upgrade APP Center beyond v1.05.21, AORUS GRAPHICS ENGINE to 1.57 or later, XTREME GAMING ENGINE to 1.26 or later, and OC GURU II to a release beyond v2.08. Because the drivers can remain loaded even after the utilities are uninstalled, check Windows systems for GPCIDrv.sys/GDrv.sys still present in the drivers directory or driver list and remove or replace vulnerable instances. Since the flaw is a local privilege escalation actively used with ransomware, prioritize hosts where an attacker may have chained it to gain elevated privileges.
| GIGABYTE APP Center | v1.05.21 and earlier |
| GIGABYTE AORUS GRAPHICS ENGINE | before 1.57 |
| GIGABYTE XTREME GAMING ENGINE | before 1.26 |
| GIGABYTE OC GURU II | v2.08 |
| GIGABYTE GPCIDrv / GDrv low-level kernel drivers (components of the above utilities) | as bundled with the listed product versions |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated privileges.
- Affected
- GIGABYTE Multiple Products
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- gigabyte
- Products
- aorus graphics engine, app center, oc guru ii, xtreme gaming engine
- Weakness
- CWE-749
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H