SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2018-19323

GIGABYTE Multiple Products Privilege Escalation Vulnerability

KEVCRITICAL 9.8EPSS 7.83%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 14 November 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes functionality to read and write Machine Specific Registers (MSRs).

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
7.83% probability · 94th percentile
CISA KEV
Listed 24 October 2022 · due 14 November 2022 · used in ransomware campaigns
Affected
gigabyte/aorus graphics engine · gigabyte/gigabyte app center · gigabyte/oc guru ii · gigabyte/xtreme gaming engine
Source
cve@mitre.org

CISA notes

Apply updates per vendor instructions. https://www.gigabyte.com/Support/Security/1801; https://nvd.nist.gov/vuln/detail/CVE-2018-19323

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.