Description
The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated privileges.
In plain language
AI Act nowThis GIGABYTE software/drivers issue can let attackers use Windows low-level access to take over your system; if you use GIGABYTE APP Center, AORUS GRAPHICS ENGINE, XTREME GAMING ENGINE, or OC GURU II (older versions), you should treat it as a serious, real-world ransomware-related risk.
CVE-2018-19322 is a local privilege escalation weakness involving GPCIDrv/GDrv low-level drivers in GIGABYTE APP Center and related GIGABYTE graphics/overclock utilities; affected versions expose functionality to read/write to I/O ports, which has been used in ransomware campaigns and is listed in CISA KEV.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply updates per vendor instructions.
References
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2018-19322 and every CVE in our database. Create a free account — no credit card required.
Create Free Account