Vulnerability record · CVE-2018-19320 · published 21 December 2018
CVE-2018-19320: GIGABYTE GDrv driver exposes ring0 memory write to local attackers
Gigabyte · Aorus Graphics Engine
The GDrv low-level driver shipped with GIGABYTE APP Center, AORUS GRAPHICS ENGINE, XTREME GAMING ENGINE and OC GURU II exposes memcpy-like functionality that runs at ring0. Any local user who can reach the driver interface can abuse that primitive to overwrite kernel memory and take full control of the machine.
Description
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes ring0 memcpy-like functionality that could allow a local attacker to take complete control of the affected system.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is in CISA KEV with a ransomware campaign flag and gives full system control, but exploitation requires local access and the EPSS score is modest.
What it is
The GDrv low-level driver shipped with GIGABYTE APP Center, AORUS GRAPHICS ENGINE, XTREME GAMING ENGINE and OC GURU II exposes memcpy-like functionality that runs at ring0. Any local user who can reach the driver interface can abuse that primitive to overwrite kernel memory and take full control of the machine.
Impact
An attacker gains kernel-level read/write, which converts a normal user session into complete control of the affected system, including the ability to disable protections and persist.
Attack surface
Reached locally through the installed GIGABYTE driver interface; the CVSS vector is AV:L/PR:L/UI:N, so a low-privileged local account is required and no user interaction is needed. No remote or network path is described.
Exploitation
CISA added it to KEV on 2022-10-24 with a known ransomware campaign flag, and public exploit references exist, though EPSS 30-day probability is only about 3.6 percent.
What to do
- Apply the vendor updates listed on GIGABYTE's security advisory page for APP Center, AORUS GRAPHICS ENGINE, XTREME GAMING ENGINE and OC GURU II.
- If patching is not immediately possible, remove or disable the GDrv driver and the associated GIGABYTE utilities on systems that do not need them.
- Restrict local interactive logon and administrative rights so untrusted users cannot run code on hosts carrying the driver.
- Monitor for reinstallation of the vulnerable utilities by users or software deployment after remediation.
Detection
- Hunt for the GDrv driver file and GIGABYTE utility install paths on endpoints and flag hosts still running them.
- Alert on driver load events for GDrv.sys and on unexpected processes opening a handle to that device.
- Correlate local privilege-escalation behavior, such as a non-system process writing to kernel memory or loading unsigned drivers, with GIGABYTE utility presence.
- Review EDR telemetry for known exploit tooling that targets this driver family.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2018-19320 to the Known Exploited Vulnerabilities catalog on 24 October 2022 as "GIGABYTE Multiple Products Unspecified Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 14 November 2022.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://seclists.org/fulldisclosure/2018/Dec/39 | ExploitMailing ListThird Party Advisory |
| http://www.securityfocus.com/bid/106252 | Broken LinkThird Party AdvisoryVDB Entry |
| https://www.gigabyte.com/Support/Security/1801 | Vendor Advisory |
| https://www.gigabyte.com/tw/Support/Utility/Graphics-Card | Product |
| https://www.secureauth.com/labs/advisories/gigabyte-drivers-elevation-privilege-vulnerabilities | Broken LinkExploitThird Party Advisory |
| http://seclists.org/fulldisclosure/2018/Dec/39 | ExploitMailing ListThird Party Advisory |
| http://www.securityfocus.com/bid/106252 | Broken LinkThird Party AdvisoryVDB Entry |
| https://www.gigabyte.com/Support/Security/1801 | Vendor Advisory |
| https://www.gigabyte.com/tw/Support/Utility/Graphics-Card | Product |
| https://www.secureauth.com/labs/advisories/gigabyte-drivers-elevation-privilege-vulnerabilities | Broken LinkExploitThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-19320 | US Government Resource |
Track CVE-2018-19320 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-19320), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.