Skip to content
COOEY

EXPOSURES › CVE-2018-19322

CVE-2018-19322

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-10-24 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2018-19322 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 ransomwarerceexploited-in-wildunpatched

GIGABYTE low-level drivers in multiple products allowed remote code execution via IO port access, leading to ransomware exploitation.

GIGABYTE's GPCIDrv and GDrv drivers in App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II exposed IO port read/write functionality, enabling elevated privilege code execution. This vulnerability was actively exploited in the wild and linked to ransomware, meaning DIB organizations using GIGABYTE hardware must verify patching status and monitor for supply-chain compromises. The failure is avoidable through timely patching and highlights the risk of unpatched, exploited-in-wild vulnerabilities in widely deployed hardware.

Shame score — A critical, actively exploited vulnerability in widely deployed hardware drivers that enabled ransomware attacks, demonstrating severe negligence in patch management and supply-chain security.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated privileges.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.