CVE-2018-19321
GIGABYTE Multiple Products: Privilege Escalation
As of , CVE-2018-19321 in GIGABYTE Multiple Products is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.
- Exploited
- Yes: CISA listed it on 24 October 2022
- US federal deadline
- 14 November 202221 days after CISA listed it. US federal civilian agencies must fix it by then.
- Used in ransomware campaigns
- Known
- EPSS score
- 0.04Higher than 89% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
- EPSS when listed
- 0.02 on 24 October 2022EPSS on the day CISA listed it.
- Public exploit
- None foundNeither Metasploit nor Exploit-DB lists one.
- Fix
- Vendor advice: www.gigabyte.comLinks below, from CISA's entry.
What CISA says to do
Apply updates per vendor instructions.
CISA's required action
What the flaw is
The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.
CISA's description
The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.
The CVE record's description, from mitre
- CVE published
- 21 December 2018
- Assigned by
- mitre
- CVSS
- 7.8 High (CVSS 3.1, from CISA-ADP)
- CISA SSVC, exploitation
- active
- CISA SSVC, automatable
- no
- CISA SSVC, technical impact
- total
Timeline
- The CVE record was published.
- CISA added it to its list of exploited vulnerabilities.
- The US federal deadline to fix it.
Multiple Products: other exploited entries
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2018-19323Privilege Escalation | GIGABYTE Multiple Products | Patch this weekRansomware use | 0.08 | ||
| CVE-2018-19320Unspecified | GIGABYTE Multiple Products | Patch this weekRansomware use | 0.04 | ||
| CVE-2018-19322Code Execution | GIGABYTE Multiple Products | Patch this weekRansomware use | 0.02 |
Read further
- CVE recordcve.org
- NVD entrynvd.nist.gov
- CISA's catalogcisa.gov
- EPSS for this CVEapi.first.org