Junglewise Threat Intelligence

CVE-2018-19322: GIGABYTE Multiple Products Code Execution Vulnerability

CVE-2018-19322 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-10-24

Technologies: Apple Multiple Products. Vendors: Apple.

Executive brief

The GPCIDrv and GDrv low-level drivers in multiple GIGABYTE products expose functionality to read/write data from/to IO ports. Local attackers can leverage this to execute arbitrary code with elevated privileges.

Affected products

  • GIGABYTE APP Center v1.05.21 and earlier
  • GIGABYTE AORUS GRAPHICS ENGINE before 1.57
  • GIGABYTE XTREME GAMING ENGINE before 1.26
  • GIGABYTE OC GURU II v2.08

Timeline

  • 2018-12-18: disclosed: Initial disclosure on Seclists Full Disclosure mailing list
  • 2022-10-24: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats