← Vulnerability feed

Vulnerability record · CVE-2018-19320 · published 21 December 2018

CVE-2018-19320: GIGABYTE GDrv driver exposes ring0 memory write to local attackers

Gigabyte · Aorus Graphics Engine

The GDrv low-level driver shipped with GIGABYTE APP Center, AORUS GRAPHICS ENGINE, XTREME GAMING ENGINE and OC GURU II exposes memcpy-like functionality that runs at ring0. Any local user who can reach the driver interface can abuse that primitive to overwrite kernel memory and take full control of the machine.

7.8 CVSS 3.1 High CISA KEV since 24 Oct 2022 Known ransomware use EPSS 3.6% · top 11.0%
7.8CVSS 3.1 base score, v2 7.2
3.6%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
4Affected product versions listed by NVD
11References, 4 tagged exploit
13 Aug 2026Last modified by NVD

Description

The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes ring0 memcpy-like functionality that could allow a local attacker to take complete control of the affected system.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityIt is in CISA KEV with a ransomware campaign flag and gives full system control, but exploitation requires local access and the EPSS score is modest.

What it is

The GDrv low-level driver shipped with GIGABYTE APP Center, AORUS GRAPHICS ENGINE, XTREME GAMING ENGINE and OC GURU II exposes memcpy-like functionality that runs at ring0. Any local user who can reach the driver interface can abuse that primitive to overwrite kernel memory and take full control of the machine.

Impact

An attacker gains kernel-level read/write, which converts a normal user session into complete control of the affected system, including the ability to disable protections and persist.

Attack surface

Reached locally through the installed GIGABYTE driver interface; the CVSS vector is AV:L/PR:L/UI:N, so a low-privileged local account is required and no user interaction is needed. No remote or network path is described.

Exploitation

CISA added it to KEV on 2022-10-24 with a known ransomware campaign flag, and public exploit references exist, though EPSS 30-day probability is only about 3.6 percent.

What to do

  • Apply the vendor updates listed on GIGABYTE's security advisory page for APP Center, AORUS GRAPHICS ENGINE, XTREME GAMING ENGINE and OC GURU II.
  • If patching is not immediately possible, remove or disable the GDrv driver and the associated GIGABYTE utilities on systems that do not need them.
  • Restrict local interactive logon and administrative rights so untrusted users cannot run code on hosts carrying the driver.
  • Monitor for reinstallation of the vulnerable utilities by users or software deployment after remediation.

Detection

  • Hunt for the GDrv driver file and GIGABYTE utility install paths on endpoints and flag hosts still running them.
  • Alert on driver load events for GDrv.sys and on unexpected processes opening a handle to that device.
  • Correlate local privilege-escalation behavior, such as a non-system process writing to kernel memory or loading unsigned drivers, with GIGABYTE utility presence.
  • Review EDR telemetry for known exploit tooling that targets this driver family.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2018-19320 to the Known Exploited Vulnerabilities catalog on 24 October 2022 as "GIGABYTE Multiple Products Unspecified Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 14 November 2022.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-19320 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2018-19320), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.