EXPOSURES › CVE-2018-19320
CVE-2018-19320
CRITICAL ⌖ ON CISA KEV · EXPLOITEDGIGABYTE drivers exposed ring0 memcpy functionality allowing local attackers to take full system control.
GIGABYTE's GDrv low-level driver in multiple products exposed ring0 memcpy-like functionality, enabling a local attacker to gain complete control of the system. This is a critical failure because it represents a severe privilege escalation and remote code execution vector if combined with other vulnerabilities, directly impacting DIB organizations that rely on GIGABYTE hardware for secure workstations. Organizations must ensure all GIGABYTE drivers are patched and evaluate the risk of local privilege escalation in their environment.
Shame score — A critical ring0 vulnerability in widely shipped GIGABYTE drivers that allows complete system control, indicating a severe lack of secure coding practices and prolonged exposure to exploitation.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
The GDrv low-level driver in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II exposes ring0 memcpy-like functionality that could allow a local attacker to take complete control of the affected system.