CVE-2018-19320 is a critical vulnerability affecting the GDrv low-level driver found in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08. This flaw exposes ring0 memcpy-like functionality, allowing a local attacker to achieve complete system control. With a CVSS score of 7.8 (HIGH), the vulnerability is easily exploitable with low attack complexity and no user interaction required, leading to high impacts on confidentiality, integrity, and availability. Notably, this CVE is actively exploited in the wild, including in known ransomware campaigns, and has garnered significant community discussion and media coverage, despite a lack of public exploit code on platforms like Metasploit or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.57CPE matchmatch criteria | cpe:2.3:a:gigabyte:aorus_graphics_engine:*:*:*:*:*:*:*:* | ||
< 19.0422.1CPE matchmatch criteria | cpe:2.3:a:gigabyte:app_center:*:*:*:*:*:*:*:* | ||
2.08CPE matchmatch criteria | cpe:2.3:a:gigabyte:oc_guru_ii:2.08:*:*:*:*:*:*:* | ||
< 1.26CPE matchmatch criteria | cpe:2.3:a:gigabyte:xtreme_gaming_engine:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.