LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2018-19322: GIGABYTE Multiple Products Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Oct 24, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Nov 14, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2018-19322 to its Known Exploited Vulnerabilities catalog on Oct 24, 2022, with a federal patch deadline of Nov 14, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read/write data from/to IO ports. This could be…

CVE-2018-19322 is a code-execution vulnerability affecting multiple GIGABYTE software packages that ship low-level drivers. Those drivers expose unrestricted access to hardware I/O ports, which an attacker who already has a foothold can abuse to run code with elevated privileges. Because the flaw has been observed in ransomware campaigns, organizations that run the affected GIGABYTE utilities should treat it as a high-priority local-privilege-escalation risk.

The issue resides in the GPCIDrv and GDrv drivers bundled with GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II. Public detail beyond the CISA summary is limited; exact affected versions and patch identifiers must be confirmed against the vendor advisory.

How it works

The underlying weakness is CWE-749 (Exposed Dangerous Method or Function). The drivers intentionally export interfaces that let user-mode code read from and write to arbitrary I/O ports. On modern Windows systems those ports control critical hardware resources; an attacker who can issue the right port operations can therefore manipulate kernel memory, disable security features, or inject shellcode that executes with SYSTEM privileges.

No remote network vector is described; exploitation requires local code execution first (for example via a malicious document, installer, or another vulnerability). Once that foothold exists, the exposed driver interfaces become a reliable privilege-escalation path. Specific exploit mechanics are not provided in the public record and should not be assumed; defenders should treat any unauthorized use of the named drivers as suspicious.

Am I affected? How to find it in your systems

These packages are commonly installed on desktops and workstations that use GIGABYTE motherboards, graphics cards, or gaming peripherals. They may also appear on systems where an end user or OEM image added the utilities for overclocking or RGB control.

How to remediate

Apply the vendor-supplied updates for the affected products exactly as directed in the GIGABYTE advisory. CISA’s required action is simply “Apply updates per vendor instructions.” After patching, reboot to ensure the vulnerable drivers are unloaded and replaced.

If you can't patch immediately

Until the official update can be deployed, reduce exposure with compensating controls:

If your data may have been exposed

Actively exploited local-privilege-escalation flaws are frequently chained with ransomware. If systems running the vulnerable drivers show signs of compromise, assume the attacker obtained elevated access and treat the incident as a potential breach. Rotate credentials, isolate affected hosts, and perform forensic review. As an additional check, individuals can run a free exposure scan of their work email addresses against known breach data sets to determine whether credentials or personal information have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedGIGABYTE · Multiple Products
WeaknessCWE-749
Added to CISA KEVOct 24, 2022
Federal patch deadlineNov 14, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities