SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2018-19321

GIGABYTE Multiple Products Privilege Escalation Vulnerability

KEVHIGH 7.8EPSS 3.67%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 14 November 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.

CVSS 3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
3.67% probability · 89th percentile
CISA KEV
Listed 24 October 2022 · due 14 November 2022 · used in ransomware campaigns
Affected
gigabyte/aorus graphics engine · gigabyte/app center · gigabyte/oc guru ii · gigabyte/xtreme gaming engine
Source
cve@mitre.org

CISA notes

Apply updates per vendor instructions. https://www.gigabyte.com/Support/Security/1801; https://nvd.nist.gov/vuln/detail/CVE-2018-19321

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.