EXPOSURES › CVE-2018-19321
CVE-2018-19321
CRITICAL ⌖ ON CISA KEV · EXPLOITEDGIGABYTE drivers allowed local privilege escalation via arbitrary memory read/write, enabling ransomware entry.
GIGABYTE's GPCIDrv and GDrv drivers exposed arbitrary physical memory access, allowing local attackers to escalate privileges. This is critical for DIBs because it provides a direct path for ransomware to gain system control, violating CMMC/NIST 800-171 requirements for patch management and access control. Organizations must verify GIGABYTE hardware and software are patched and avoid relying on unpatched drivers.
Shame score — A privilege escalation vulnerability in widely shipped drivers that was actively exploited in the wild and linked to ransomware, indicating severe negligence and avoidable risk.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.