Junglewise Threat Intelligence

CVE-2018-19323: GIGABYTE Multiple Products Privilege Escalation Vulnerability

CVE-2018-19323 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-10-24

Technologies: Apple Multiple Products. Vendors: Apple.

Executive brief

The GDrv low-level driver in multiple GIGABYTE products exposes functionality to read and write Machine Specific Registers (MSRs) and arbitrary physical memory. This vulnerability allows for local privilege escalation or remote exploitation depending on the environment.

Affected products

  • GIGABYTE APP Center v1.05.21 and earlier
  • GIGABYTE AORUS GRAPHICS ENGINE before 1.57
  • GIGABYTE XTREME GAMING ENGINE before 1.26
  • GIGABYTE OC GURU II v2.08

Timeline

  • 2018-12-18: disclosed: Initial disclosure via Full Disclosure mailing list
  • 2022-10-24: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats