CVE-2018-19321
Description
The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.
In plain language
AI Act nowCVE-2018-19321 is a serious GIGABYTE software/driver flaw that can let an attacker misuse low-level memory on a GIGABYTE PC, and it has been used in ransomware attacks—so small businesses that have these tools installed should act now.
CVE-2018-19321 is a local privilege-escalation weakness in GIGABYTE APP Center and related low-level graphics/overclocking components (GPCIDrv/GDrv), where exposed driver functionality can be used to read/write arbitrary physical memory; the issue is confirmed in CISA KEV and has been used in ransomware campaigns, with fixed versions available.
What to do now
- Check whether any of these are installed on business PCs: GIGABYTE APP Center (v1.05.21 or earlier), AORUS GRAPHICS ENGINE (before 1.57), XTREME GAMING ENGINE (before 1.26), or OC GURU II (v2.08 or earlier).
- If affected, upgrade AORUS GRAPHICS ENGINE to 1.57.
- If affected, upgrade XTREME GAMING ENGINE to 1.26.
- If affected, upgrade OC GURU II to a version newer than 2.08 (use the vendor security update instructions).
- If affected, upgrade GIGABYTE APP Center to 19.0422.1.
- Recheck versions after updating to confirm the fixes are applied.
- If you cannot upgrade quickly, disable/uninstall the vulnerable GIGABYTE components until updates are deployed (and remove them from automatic startup).
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply updates per vendor instructions.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2018-19321 and every CVE in our database. Create a free account — no credit card required.
Create Free Account