CVE-2018-19322

GIGABYTE Multiple Products: Code Execution

As of , CVE-2018-19322 in GIGABYTE Multiple Products is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.

Exploited
Yes: CISA listed it on 24 October 2022
US federal deadline
14 November 202221 days after CISA listed it. US federal civilian agencies must fix it by then.
Used in ransomware campaigns
Known
EPSS score
0.02Higher than 77% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
EPSS when listed
0.01 on 24 October 2022EPSS on the day CISA listed it.
Public exploit
None foundNeither Metasploit nor Exploit-DB lists one.
Fix
Vendor advice: www.gigabyte.comLinks below, from CISA's entry.

What CISA says to do

Apply updates per vendor instructions.

CISA's required action

What the flaw is

The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated privileges.

CISA's description

The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated privileges.

The CVE record's description, from mitre

CVE published
21 December 2018
Assigned by
mitre
CVSS
7.8 High (CVSS 3.1, from CISA-ADP)
CWE-749
Exposed Dangerous Method or Function
CISA SSVC, exploitation
active
CISA SSVC, automatable
no
CISA SSVC, technical impact
total

Timeline

  1. The CVE record was published.
  2. CISA added it to its list of exploited vulnerabilities.
  3. The US federal deadline to fix it.

Multiple Products: other exploited entries

VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2018-19323Privilege EscalationGIGABYTE Multiple ProductsPatch this weekRansomware use0.08
CVE-2018-19320UnspecifiedGIGABYTE Multiple ProductsPatch this weekRansomware use0.04
CVE-2018-19321Privilege EscalationGIGABYTE Multiple ProductsPatch this weekRansomware use0.04

Read further