ZeroHour

CVE-2018-19322

KEV ransomware PoC ×2mass

Elevated-privilege code execution via GIGABYTE GPCIDrv/GDrv kernel drivers

CISA: GIGABYTE Multiple Products Code Execution Vulnerability

CVSS 3.1
7.8 high
EPSS
2%p77
Published
()
KEV added
AI analysis

The GPCIDrv and GDrv low-level kernel drivers bundled with GIGABYTE APP Center (v1.05.21 and earlier), AORUS GRAPHICS ENGINE (before 1.57), XTREME GAMING ENGINE (before 1.26) and OC GURU II (v2.08) expose functionality that lets user-mode code read and write system IO ports. Any local, unprivileged process on a Windows host where the driver is loaded can invoke this exposed interface, and the arbitrary IO port read/write primitive can be leveraged in several ways to ultimately run code with elevated privileges — a local privilege escalation (CVSS 3.1 score 7.8, local attack vector, high impact). Affected users are owners of GIGABYTE motherboards or graphics cards who installed any of the four listed utilities, with the important caveat that the low-level drivers can remain installed and loaded even after the utility itself is uninstalled. Exploitation is confirmed: CISA added the flaw to its KEV catalog on 2022-10-24 with known ransomware use, and reporting at the time noted hackers actively exploiting it (alongside the Cisco AnyConnect flaw) in ransomware campaigns.

What to do: Apply updates per vendor instructions: upgrade APP Center beyond v1.05.21, AORUS GRAPHICS ENGINE to 1.57 or later, XTREME GAMING ENGINE to 1.26 or later, and OC GURU II to a release beyond v2.08. Because the drivers can remain loaded even after the utilities are uninstalled, check Windows systems for GPCIDrv.sys/GDrv.sys still present in the drivers directory or driver list and remove or replace vulnerable instances. Since the flaw is a local privilege escalation actively used with ransomware, prioritize hosts where an attacker may have chained it to gain elevated privileges.

Affected
GIGABYTE APP Centerv1.05.21 and earlier
GIGABYTE AORUS GRAPHICS ENGINEbefore 1.57
GIGABYTE XTREME GAMING ENGINEbefore 1.26
GIGABYTE OC GURU IIv2.08
GIGABYTE GPCIDrv / GDrv low-level kernel drivers (components of the above utilities)as bundled with the listed product versions
Estimated exposure
mass≈ millions of Windows systems plausibly carrying the GPCIDrv/GDrv driver (utilities shipped with GIGABYTE boards/GPUs); actual exploited systems limited to… — Estimated from GIGABYTE's position as a top-tier motherboard and graphics-card vendor whose APP Center, OC GURU II and AORUS/XTREME engines shipped by default with its hardware and software suites, and whose low-level drivers can persist…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated privileges.

CISA Known Exploited Vulnerability
Affected
GIGABYTE Multiple Products
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
gigabyte
Products
aorus graphics engine, app center, oc guru ii, xtreme gaming engine
Weakness
CWE-749
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news