Umbra Wiki cve cve/CVE-2018-19320
Back to wiki

CVE-2018-19320 — GIGABYTE Multiple Products Unspecified Vulnerability

provenance: imported · CVE: CVE-2018-19320

CVE-2018-19320: GIGABYTE Multiple Products Unspecified Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project GIGABYTE
Product Multiple Products
Date added 2022-10-24
Due date 2022-11-14
Ransomware campaign use Known

Description

The GDrv low-level driver in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II exposes ring0 memcpy-like functionality that could allow a local attacker to take complete control of the affected system.

Required action (CISA)

Apply updates per vendor instructions.

Notes

https://www.gigabyte.com/Support/Security/1801; https://nvd.nist.gov/vuln/detail/CVE-2018-19320

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2018-19320
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog