CVE-2018-19323
KEV ransomware PoC ×2massPrivilege Escalation in GIGABYTE GDrv Driver (APP Center, AORUS, OC GURU II, XTREME)
CISA: GIGABYTE Multiple Products Privilege Escalation Vulnerability
The GDrv low-level kernel driver bundled with GIGABYTE's APP Center (1.05.21 and earlier), AORUS GRAPHICS ENGINE (before 1.57), XTREME GAMING ENGINE (before 1.26), and OC GURU II (2.08) exposes functionality that allows reading and writing Machine Specific Registers (MSRs) without sufficient access control. An attacker who reaches this exposed driver functionality can send crafted requests to write arbitrary MSRs, gaining kernel (ring-0) privileges and thereby escalating from limited access to full control of the host. The flaw is rated critical (CVSS 9.8) with no privileges or user interaction required per the published vector. It affects Windows systems where the GIGABYTE utility software that installs the GDrv driver is present, typically enthusiast overclocking and monitoring tools bundled with GIGABYTE motherboards and graphics cards. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-10-24 with known ransomware use, and recent reporting indicates active exploitation alongside other driver vulnerabilities.
What to do: Apply vendor updates per CISA guidance: APP Center later than 1.05.21, AORUS GRAPHICS ENGINE 1.57 or later, XTREME GAMING ENGINE 1.26 or later, and OC GURU II later than 2.08, which ship a corrected GDrv driver. Audit Windows endpoints for the GDrv (gdrv.sys) low-level driver and uninstall unused GIGABYTE utility software to close the exposed interface. Because CISA lists this with known ransomware use, prioritize remediation on workstations and user endpoints rather than assuming only servers are affected.
| GIGABYTE APP Center | 1.05.21 and earlier |
| GIGABYTE AORUS GRAPHICS ENGINE | before 1.57 |
| GIGABYTE XTREME GAMING ENGINE | before 1.26 |
| GIGABYTE OC GURU II | 2.08 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes functionality to read and write Machine Specific Registers (MSRs).
- Affected
- GIGABYTE Multiple Products
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- gigabyte
- Products
- aorus graphics engine, gigabyte app center, oc guru ii, xtreme gaming engine
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H