Record summary

CVE-2018-19321 has a selected CVSS score of 7.8 (high); EIP currently links 2 repository PoCs. CISA lists CVE-2018-19321 in KEV and reports its use in known ransomware campaigns.

Description

The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Oct 24, 2022 · CISA
VulnCheck KEV
Listed · Oct 24, 2022 · VulnCheck
Reported exploitation
Observed · VulnCheck
Ransomware use
Observed · CISA

Available material

Repository PoCs
2

CISA SSVC decision

ExploitationActive
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 27, 2022 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CISAVersion data not supplied

Proofs of concept

2

Repository PoCs

GitHubnanabingies/Driver-RWRepository PoCby nanabingiesStars: 8Not analyzed8 files

13.0 KiB

GitHub

PoC details
GitHubnanabingies/CVE-2018-19321Repository PoCby nanabingiesStars: 2Not analyzed3 files

8.9 KiB

GitHub

PoC details

References

6