20181221 [CORE-2018-0007] - GIGABYTE Driver Elevation of Privilege Vulnerabilitiesmailing list
http://seclists.org/fulldisclosure/2018/Dec/39 CVE-2018-19320
HIGHCISA KEVRansomware
GIGABYTE Multiple Products Unspecified Vulnerability
Record summary
CVE-2018-19320 has a selected CVSS score of 7.8 (high); EIP currently links 3 repository PoCs. CISA lists CVE-2018-19320 in KEV and reports its use in known ransomware campaigns.
Description
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes ring0 memcpy-like functionality that could allow a local attacker to take complete control of the affected system.
Description source: CVE List
Exploitation context
Known exploitation
- CISA KEV
- Listed · Oct 24, 2022 · CISA
- VulnCheck KEV
- Listed · Feb 10, 2020 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
- Ransomware use
- Observed · CISA
Available material
- Repository PoCs
- 3
CISA SSVC decision
ExploitationActive
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 27, 2022 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Multiple ProductsBrowse GIGABYTE / Multiple Products | CISA | Version data not supplied | |
Proofs of concept
3Repository PoCs
GitHubASkyeye/CVE-2018-19320Repository PoCby ASkyeyeStars: 19Not analyzed9 files
GitHubhmnthabit/CVE-2018-19320-LPERepository PoCby hmnthabitStars: 11Not analyzed7 files
GitHubzer0condition/GDRVLoaderRepository PoCby zer0conditionStars: 370Not analyzed18 files
References
7106252vdb entry
http://www.securityfocus.com/bid/106252 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-19320 cisa.govGovernment resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-19320 gigabyte.comConfirmation
https://www.gigabyte.com/Support/Security/1801 gigabyte.comConfirmation
https://www.gigabyte.com/tw/Support/Utility/Graphics-Card secureauth.com
https://www.secureauth.com/labs/advisories/gigabyte-drivers-elevation-privilege-vulnerabilities