⚠️ CISA Known Exploited Vulnerability
Active ThreatThis vulnerability is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. Active exploitation has been observed in the wild. This poses significant risk to federal enterprises and should be prioritized for immediate patching.
CVE-2018-19323
Critical CISA KEVVulnerability Description
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes functionality to read and write Machine Specific Registers (MSRs).
CVSS Metrics
Common Vulnerability Scoring System
Vector String:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Known Affected Software
3 configuration(s) from 1 vendor(s)
cpe:2.3:a:gigabyte:xtreme_gaming_engine:1.25:*:*:*:*:*:*:*
cpe:2.3:a:gigabyte:oc_guru_ii:2.08:*:*:*:*:*:*:*
cpe:2.3:a:gigabyte:xtreme_gaming_engine:1.22:*:*:*:*:*:*:*
References & Resources
-
http://seclists.org/fulldisclosure/2018/Dec/39cve@mitre.org Exploit Mailing List Third Party Advisory
-
http://www.securityfocus.com/bid/106252cve@mitre.org Broken Link Third Party Advisory VDB Entry
-
https://www.gigabyte.com/Support/Security/1801cve@mitre.org Vendor Advisory
-
https://www.gigabyte.com/tw/Support/Utility/Graphics-Cardcve@mitre.org Product
-
https://www.secureauth.com/labs/advisories/gigabyte-drivers-elevation-privilege-vulnerabilitiescve@mitre.org Broken Link Exploit Third Party Advisory
-
http://seclists.org/fulldisclosure/2018/Dec/39af854a3a-2127-422b-91ae-364da2661108 Exploit Mailing List Third Party Advisory
-
http://www.securityfocus.com/bid/106252af854a3a-2127-422b-91ae-364da2661108 Broken Link Third Party Advisory VDB Entry
-
https://www.gigabyte.com/Support/Security/1801af854a3a-2127-422b-91ae-364da2661108 Vendor Advisory
-
https://www.gigabyte.com/tw/Support/Utility/Graphics-Cardaf854a3a-2127-422b-91ae-364da2661108 Product
-
https://www.secureauth.com/labs/advisories/gigabyte-drivers-elevation-privilege-vulnerabilitiesaf854a3a-2127-422b-91ae-364da2661108 Broken Link Exploit Third Party Advisory
-
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-19323134c704f-9b21-4f2e-91b3-4a467353bcc0 US Government Resource
Severity Details
CISA KEV Status
Listed in CISA's Known Exploited Vulnerabilities catalog
Key Information
- Published Date
- December 21, 2018
