← Vulnerability feed

Vulnerability record · CVE-2018-19321 · published 21 December 2018

CVE-2018-19321: GIGABYTE driver exposes arbitrary physical memory read/write

Gigabyte · Aorus Graphics Engine

The GPCIDrv and GDrv low-level drivers shipped with GIGABYTE APP Center (v1.05.21 and earlier), AORUS GRAPHICS ENGINE (before 1.57), XTREME GAMING ENGINE (before 1.26) and OC GURU II (v2.08) expose functionality that lets a caller read and write arbitrary physical memory. Because the drivers run in kernel mode, this primitive undermines the OS security boundary and is a well-known route to local privilege escalation.

7.8 CVSS 3.1 High CISA KEV since 24 Oct 2022 Known ransomware use EPSS 3.7% · top 10.7%
7.8CVSS 3.1 base score, v2 7.2
3.7%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
4Affected product versions listed by NVD
9References, 4 tagged exploit
13 Aug 2026Last modified by NVD

Description

The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityCVSS 7.8 with local privilege escalation to SYSTEM, confirmed public exploits and CISA KEV listing with known ransomware use, though exploitation requires local access.

What it is

The GPCIDrv and GDrv low-level drivers shipped with GIGABYTE APP Center (v1.05.21 and earlier), AORUS GRAPHICS ENGINE (before 1.57), XTREME GAMING ENGINE (before 1.26) and OC GURU II (v2.08) expose functionality that lets a caller read and write arbitrary physical memory. Because the drivers run in kernel mode, this primitive undermines the OS security boundary and is a well-known route to local privilege escalation.

Impact

A local attacker gains the ability to read and write arbitrary physical memory, which can be used to corrupt kernel structures and elevate privileges to SYSTEM. CISA notes known ransomware campaign use, so the primitive has been chained into real intrusion tooling.

Attack surface

Reached locally through the exposed driver interface; the CVSS vector is AV:L/PR:L/UI:N, so the attacker needs local access and low privileges but no user interaction. No remote or network vector is described.

Exploitation

CISA added it to the KEV catalog on 2022-10-24 with a 2022-11-14 due date and flags known ransomware campaign use; EPSS 30-day probability is 0.03671 (89th percentile). Public exploit references exist (Full Disclosure and SecureAuth advisories), so exploitation is proven and observed.

What to do

  • Apply the vendor updates listed in GIGABYTE's security advisory (https://www.gigabyte.com/Support/Security/1801) for APP Center, AORUS GRAPHICS ENGINE, XTREME GAMING ENGINE and OC GURU II.
  • If a patched version is not available for a given utility, uninstall it and remove the GPCIDrv/GDrv driver files from endpoints.
  • Block or alert on loading of unsigned or known-vulnerable GIGABYTE driver binaries via application control or WDAC.
  • Restrict local administrative and interactive logon rights so low-privileged users cannot reach the driver interface.
  • Treat any host with these utilities as compromised if unexplained SYSTEM-level activity is observed, and reimage rather than clean.

Detection

  • Hunt for GPCIDrv.sys and GDrv.sys (or similarly named GIGABYTE driver files) loaded on endpoints, especially outside expected gaming or overclocking use.
  • Monitor for driver load events (e.g., Sysmon Event ID 6) referencing GIGABYTE driver paths or hashes.
  • Alert on processes opening device handles to the GIGABYTE driver device objects from non-GIGABYTE binaries.
  • Correlate local privilege escalation telemetry (token manipulation, unexpected SYSTEM process creation) on hosts where these drivers are present.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2018-19321 to the Known Exploited Vulnerabilities catalog on 24 October 2022 as "GIGABYTE Multiple Products Privilege Escalation Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 14 November 2022.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-19321 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2018-19321), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.