Skip to content
COOEY

EXPOSURES › CVE-2018-19321

CVE-2018-19321

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-10-24 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2018-19321 ↗
⌖ EXPLOITED IN THE WILD SHAME 78/100 ransomwareexploited-in-wildprivilege-escalation

GIGABYTE drivers allowed local privilege escalation via arbitrary memory read/write, enabling ransomware entry.

GIGABYTE's GPCIDrv and GDrv drivers exposed arbitrary physical memory access, allowing local attackers to escalate privileges. This is critical for DIBs because it provides a direct path for ransomware to gain system control, violating CMMC/NIST 800-171 requirements for patch management and access control. Organizations must verify GIGABYTE hardware and software are patched and avoid relying on unpatched drivers.

Shame score — A privilege escalation vulnerability in widely shipped drivers that was actively exploited in the wild and linked to ransomware, indicating severe negligence and avoidable risk.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.