CVE-2018-19323
gigabyte aorus graphics engine, gigabyte app center, gigabyte oc guru ii
Published 21 Dec 2018 · updated 1 Oct 2026 · Analyzed
9.8 Critical · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 24 Oct 2022, with a remediation deadline of 14 Nov 2022 for US federal agencies. It has been used in ransomware campaigns.
Required action: Apply updates per vendor instructions.
Description
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes functionality to read and write Machine Specific Registers (MSRs).
References
- seclists.org/fulldisclosure/2018/Dec/39 · Exploit, Mailing List, Third Party Advisory
- www.securityfocus.com/bid/106252 · Broken Link, Third Party Advisory, VDB Entry
- www.gigabyte.com/Support/Security/1801 · Vendor Advisory
- www.gigabyte.com/tw/Support/Utility/Graphics-Card · Product
- www.secureauth.com/labs/advisories/gigabyte-drivers-elevation-privilege-vulnerabilities · Broken Link, Exploit, Third Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-19323 · US Government Resource