EXPOSURES › CVE-2018-19323
CVE-2018-19323
CRITICAL ⌖ ON CISA KEV · EXPLOITEDGIGABYTE drivers allow local privilege escalation via arbitrary memory read/write, enabling ransomware attackers to gain system control.
GIGABYTE's GPCIDrv and GDrv drivers in multiple products expose arbitrary physical memory read/write, allowing local attackers to escalate privileges. This is critical for DIBs because it provides a direct path for ransomware to move from a compromised endpoint to full system control, violating CMMC/NIST 800-171 requirements for patch management and vulnerability mitigation. Organizations must verify that all GIGABYTE hardware and software are patched to the latest versions and restrict local administrative privileges.
Shame score — A privilege escalation vulnerability in widely deployed GIGABYTE drivers was actively exploited in the wild by ransomware groups, demonstrating severe negligence in patching and security design.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.