LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2018-19321: GIGABYTE Multiple Products Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Oct 24, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Nov 14, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2018-19321 to its Known Exploited Vulnerabilities catalog on Oct 24, 2022, with a federal patch deadline of Nov 14, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read and write arbitrary physical memory. This could…

CVE-2018-19321 is a local privilege-escalation vulnerability affecting multiple GIGABYTE software packages. The GPCIDrv and GDrv low-level drivers included with GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose interfaces that let a process read and write arbitrary physical memory. A local attacker who already has a foothold on the system can abuse those interfaces to elevate privileges.

The issue is material for defenders because it has been observed in ransomware campaigns. Once elevated, an attacker can disable security tools, move laterally, or deploy ransomware with full system control. Confirm exact product versions and patch status against the vendor advisory.

How it works

The vulnerability class is improper exposure of privileged hardware access through kernel-mode drivers. GPCIDrv and GDrv provide user-mode callers with the ability to map and modify physical memory without adequate access controls. A local attacker can issue carefully crafted requests to these drivers, overwrite critical kernel structures or process tokens, and obtain SYSTEM-level privileges. Because the drivers run with high privileges by design, successful abuse bypasses normal user-mode isolation. Exact request formats and memory offsets are not detailed here; treat any public proof-of-concept material as untrusted until validated against the vendor advisory.

Am I affected? How to find it in your systems

These packages are commonly installed on Windows desktops and workstations that use GIGABYTE motherboards or graphics cards, especially systems configured for overclocking or gaming. They may also appear on enterprise machines where end users have installed vendor utilities.

Telemetry signs of exploitation are those typical of local privilege escalation: unexpected process token changes, creation of high-privilege processes from low-privilege parents, or anomalous IOCTL traffic to the named drivers. Review Windows Security event logs for privilege-use events and driver load events around the time of any suspected compromise. Absence of these indicators does not prove safety; the drivers may still be present and vulnerable.

How to remediate

Apply the updates supplied by GIGABYTE for the affected products, following the vendor’s instructions exactly. CISA’s required action is to apply those updates. After patching, verify that the vulnerable driver versions have been replaced or removed and that the software no longer loads the old drivers on boot.

Re-scan systems after remediation to confirm the drivers are no longer present or are running the fixed versions listed in the advisory.

If you can't patch immediately

Until the vendor update can be deployed, reduce the attack surface with compensating controls focused on local privilege escalation.

These steps lower risk but do not eliminate it; prioritize the official update.

If your data may have been exposed

Actively exploited privilege-escalation flaws are frequently used as a stepping stone to ransomware and data theft. If systems running the vulnerable GIGABYTE drivers show signs of compromise, assume the attacker may have obtained elevated access and treat the incident as a potential breach. Rotate credentials, isolate affected hosts, and follow your incident-response plan. As a quick check for known exposure of personal accounts, you can run a free scan of your email address against publicly disclosed breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedGIGABYTE · Multiple Products
Added to CISA KEVOct 24, 2022
Federal patch deadlineNov 14, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities