Record summary

CVE-2018-19320 has a selected CVSS score of 7.8 (high); EIP currently links 3 repository PoCs. CISA lists CVE-2018-19320 in KEV and reports its use in known ransomware campaigns.

Description

The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes ring0 memcpy-like functionality that could allow a local attacker to take complete control of the affected system.

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Oct 24, 2022 · CISA
VulnCheck KEV
Listed · Feb 10, 2020 · VulnCheck
Reported exploitation
Observed · VulnCheck
Ransomware use
Observed · CISA

Available material

Repository PoCs
3

CISA SSVC decision

ExploitationActive
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 27, 2022 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CISAVersion data not supplied

Proofs of concept

3

Repository PoCs

GitHubASkyeye/CVE-2018-19320Repository PoCby ASkyeyeStars: 19Not analyzed9 files

23.9 KiB

GitHub

PoC details
GitHubhmnthabit/CVE-2018-19320-LPERepository PoCby hmnthabitStars: 11Not analyzed7 files

327.9 KiB

GitHub

PoC details
GitHubzer0condition/GDRVLoaderRepository PoCby zer0conditionStars: 370Not analyzed18 files

455.0 KiB

GitHub

PoC details

References

7