Skip to content
COOEY

EXPOSURES › CVE-2018-19323

CVE-2018-19323

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-10-24 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2018-19323 ↗
⌖ EXPLOITED IN THE WILD SHAME 78/100 ransomwareexploited-in-wildprivilege-escalationunpatched

GIGABYTE drivers allow local privilege escalation via arbitrary memory read/write, enabling ransomware attackers to gain system control.

GIGABYTE's GPCIDrv and GDrv drivers in multiple products expose arbitrary physical memory read/write, allowing local attackers to escalate privileges. This is critical for DIBs because it provides a direct path for ransomware to move from a compromised endpoint to full system control, violating CMMC/NIST 800-171 requirements for patch management and vulnerability mitigation. Organizations must verify that all GIGABYTE hardware and software are patched to the latest versions and restrict local administrative privileges.

Shame score — A privilege escalation vulnerability in widely deployed GIGABYTE drivers was actively exploited in the wild by ransomware groups, demonstrating severe negligence in patching and security design.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.