CVE-2018-1932

MEDIUM EXPLOITED IN THE WILD RANSOMWARE

IBM API Connect <5.0.8.4 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2018-1932 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io), including in ransomware campaigns. EIP tracks 1 public exploit from researchers including BKreisel.

AI-analyzed exploit summary This is a Rust-based exploit PoC for CVE-2018-19320 and CVE-2018-19323, targeting GIGABYTE APP Center's vulnerable driver (gdrv.sys) to achieve local privilege escalation via arbitrary memory read/write and MSR manipulation.

Description

IBM API Connect 5.0.0.0 through 5.0.8.4 is affected by a vulnerability in the role-based access control in the management server that could allow an authenticated user to obtain highly sensitive information. IBM X-Force ID: 153175.

Exploits (1)

nomisec WORKING POC 2 stars
by BKreisel · poc
https://github.com/BKreisel/CVE-2018-1932X

This is a Rust-based exploit PoC for CVE-2018-19320 and CVE-2018-19323, targeting GIGABYTE APP Center's vulnerable driver (gdrv.sys) to achieve local privilege escalation via arbitrary memory read/write and MSR manipulation.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: GIGABYTE APP Center v1.05.21 and earlier
No auth needed
Prerequisites: x64 Windows system · GIGABYTE driver (gdrv.sys) loaded · Windows 10 20H1 (Build 19041)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/106486
Patch, Vendor Advisory x_refsource_confirm
http://www.ibm.com/support/docview.wss?uid=ibm10793601
VDB Entry, Vendor Advisory vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/153175

Scores

CVSS v3 4.9
EPSS 0.0323
EPSS Percentile 86.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Details

VulnCheck KEV 2023-02-14
InTheWild.io 2022-05-25
Ransomware Use Confirmed
CWE
CWE-200
Status published
Products (1)
ibm/api_connect 5.0.0.0 - 5.0.8.4
Published Jan 08, 2019
Tracked Since Feb 18, 2026