ZeroHour

CVE-2018-19323

KEV ransomware PoC ×2mass

Privilege Escalation in GIGABYTE GDrv Driver (APP Center, AORUS, OC GURU II, XTREME)

CISA: GIGABYTE Multiple Products Privilege Escalation Vulnerability

CVSS 3.1
9.8 critical
EPSS
8%p94
Published
()
KEV added
AI analysis

The GDrv low-level kernel driver bundled with GIGABYTE's APP Center (1.05.21 and earlier), AORUS GRAPHICS ENGINE (before 1.57), XTREME GAMING ENGINE (before 1.26), and OC GURU II (2.08) exposes functionality that allows reading and writing Machine Specific Registers (MSRs) without sufficient access control. An attacker who reaches this exposed driver functionality can send crafted requests to write arbitrary MSRs, gaining kernel (ring-0) privileges and thereby escalating from limited access to full control of the host. The flaw is rated critical (CVSS 9.8) with no privileges or user interaction required per the published vector. It affects Windows systems where the GIGABYTE utility software that installs the GDrv driver is present, typically enthusiast overclocking and monitoring tools bundled with GIGABYTE motherboards and graphics cards. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-10-24 with known ransomware use, and recent reporting indicates active exploitation alongside other driver vulnerabilities.

What to do: Apply vendor updates per CISA guidance: APP Center later than 1.05.21, AORUS GRAPHICS ENGINE 1.57 or later, XTREME GAMING ENGINE 1.26 or later, and OC GURU II later than 2.08, which ship a corrected GDrv driver. Audit Windows endpoints for the GDrv (gdrv.sys) low-level driver and uninstall unused GIGABYTE utility software to close the exposed interface. Because CISA lists this with known ransomware use, prioritize remediation on workstations and user endpoints rather than assuming only servers are affected.

Affected
GIGABYTE APP Center1.05.21 and earlier
GIGABYTE AORUS GRAPHICS ENGINEbefore 1.57
GIGABYTE XTREME GAMING ENGINEbefore 1.26
GIGABYTE OC GURU II2.08
Estimated exposure
mass~millions of Windows systems (GIGABYTE utility bundles install the vulnerable GDrv driver) — GIGABYTE is one of the world's largest motherboard and graphics card vendors and these utilities ship with or accompany retail boards/GPUs, implying a multi-million-system install base of the vulnerable versions, though exact counts of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes functionality to read and write Machine Specific Registers (MSRs).

CISA Known Exploited Vulnerability
Affected
GIGABYTE Multiple Products
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
gigabyte
Products
aorus graphics engine, gigabyte app center, oc guru ii, xtreme gaming engine
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news