20181221 [CORE-2018-0007] - GIGABYTE Driver Elevation of Privilege Vulnerabilitiesmailing list
http://seclists.org/fulldisclosure/2018/Dec/39 CVE-2018-19321
HIGHCISA KEVRansomware
GIGABYTE Multiple Products Privilege Escalation Vulnerability
Record summary
CVE-2018-19321 has a selected CVSS score of 7.8 (high); EIP currently links 2 repository PoCs. CISA lists CVE-2018-19321 in KEV and reports its use in known ransomware campaigns.
Description
The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.
Description source: CVE List
Exploitation context
Known exploitation
- CISA KEV
- Listed · Oct 24, 2022 · CISA
- VulnCheck KEV
- Listed · Oct 24, 2022 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
- Ransomware use
- Observed · CISA
Available material
- Repository PoCs
- 2
CISA SSVC decision
ExploitationActive
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 27, 2022 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Multiple ProductsBrowse GIGABYTE / Multiple Products | CISA | Version data not supplied | |
Proofs of concept
2Repository PoCs
GitHubnanabingies/Driver-RWRepository PoCby nanabingiesStars: 8Not analyzed8 files
GitHubnanabingies/CVE-2018-19321Repository PoCby nanabingiesStars: 2Not analyzed3 files
References
6106252vdb entry
http://www.securityfocus.com/bid/106252 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-19321 cisa.govGovernment resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-19321 gigabyte.comConfirmation
https://www.gigabyte.com/Support/Security/1801 secureauth.com
https://www.secureauth.com/labs/advisories/gigabyte-drivers-elevation-privilege-vulnerabilities