Executive brief
The GDrv low-level driver in multiple GIGABYTE products exposes functionality to read and write Machine Specific Registers (MSRs) and arbitrary physical memory. This vulnerability allows for local privilege escalation or remote exploitation depending on the environment.
Affected products
- GIGABYTE APP Center v1.05.21 and earlier
- GIGABYTE AORUS GRAPHICS ENGINE before 1.57
- GIGABYTE XTREME GAMING ENGINE before 1.26
- GIGABYTE OC GURU II v2.08
Timeline
- 2018-12-18: disclosed: Initial disclosure via Full Disclosure mailing list
- 2022-10-24: kev added: Added to CISA Known Exploited Vulnerabilities Catalog