CVE-2018-19321

gigabyte aorus graphics engine, gigabyte app center, gigabyte oc guru ii

Published 21 Dec 2018 · updated 13 Aug 2026 · Analyzed

7.8 High · CVSS 3.1, NVD

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 24 Oct 2022, with a remediation deadline of 14 Nov 2022 for US federal agencies. It has been used in ransomware campaigns.

Required action: Apply updates per vendor instructions.

Description

The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.

References