Vulnerability record · CVE-2018-19322 · published 21 December 2018
CVE-2018-19322: GIGABYTE driver IO port access allows privilege escalation
Gigabyte · Aorus Graphics Engine
The GPCIDrv and GDrv low-level drivers shipped with GIGABYTE APP Center, AORUS GRAPHICS ENGINE, XTREME GAMING ENGINE and OC GURU II expose IO port read/write functionality to user-mode callers. Because this primitive is not properly restricted, an attacker can abuse it to run code with elevated privileges. The flaw affects multiple widely installed GIGABYTE utilities, so it is relevant to any endpoint with those tools present.
Description
The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated privileges.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe vulnerability is in CISA KEV with known ransomware use and allows local privilege escalation to full system control, though it requires local access and low privileges to trigger.
What it is
The GPCIDrv and GDrv low-level drivers shipped with GIGABYTE APP Center, AORUS GRAPHICS ENGINE, XTREME GAMING ENGINE and OC GURU II expose IO port read/write functionality to user-mode callers. Because this primitive is not properly restricted, an attacker can abuse it to run code with elevated privileges. The flaw affects multiple widely installed GIGABYTE utilities, so it is relevant to any endpoint with those tools present.
Impact
An attacker who can execute code on the host gains kernel-level or SYSTEM privileges, enabling full control of the machine, persistence and disabling of security controls.
Attack surface
Reached locally through the vulnerable driver interface; the CVSS vector indicates low privileges are required and no user interaction is needed. No remote or network vector is described.
Exploitation
CVE-2018-19322 is listed in CISA KEV with a due date of 2022-11-14 and is flagged for known ransomware campaign use; EPSS 30-day probability is about 1.8 percent (77th percentile). Public exploit references exist in the advisory and mailing list entries.
What to do
- Apply the vendor updates referenced in GIGABYTE's security advisory (https://www.gigabyte.com/Support/Security/1801) and upgrade the affected utilities to fixed versions.
- If patching is not immediately possible, remove or disable the GIGABYTE APP Center, AORUS GRAPHICS ENGINE, XTREME GAMING ENGINE and OC GURU II software and their drivers from endpoints that do not require them.
- Restrict local administrative rights and monitor for non-admin processes loading GPCIDrv or GDrv.
- Block or alert on driver load events for the affected driver files via application control or WDAC policies.
Detection
- Hunt for driver load events (Sysmon Event ID 6) referencing GPCIDrv or GDrv, especially from non-standard or user-writable paths.
- Monitor for processes that load the vulnerable drivers and subsequently perform privileged operations or spawn elevated children.
- Alert on creation or modification of the affected GIGABYTE utility binaries and drivers on endpoints.
- Review endpoint inventory for installations of APP Center, AORUS GRAPHICS ENGINE, XTREME GAMING ENGINE and OC GURU II to scope exposure.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2018-19322 to the Known Exploited Vulnerabilities catalog on 24 October 2022 as "GIGABYTE Multiple Products Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 14 November 2022.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://seclists.org/fulldisclosure/2018/Dec/39 | ExploitMailing ListThird Party Advisory |
| http://www.securityfocus.com/bid/106252 | Broken LinkThird Party AdvisoryVDB Entry |
| https://www.gigabyte.com/Support/Security/1801 | Vendor Advisory |
| https://www.gigabyte.com/tw/Support/Utility/Graphics-Card | Product |
| https://www.secureauth.com/labs/advisories/gigabyte-drivers-elevation-privilege-vulnerabilities | Broken LinkExploitThird Party Advisory |
| http://seclists.org/fulldisclosure/2018/Dec/39 | ExploitMailing ListThird Party Advisory |
| http://www.securityfocus.com/bid/106252 | Broken LinkThird Party AdvisoryVDB Entry |
| https://www.gigabyte.com/Support/Security/1801 | Vendor Advisory |
| https://www.gigabyte.com/tw/Support/Utility/Graphics-Card | Product |
| https://www.secureauth.com/labs/advisories/gigabyte-drivers-elevation-privilege-vulnerabilities | Broken LinkExploitThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-19322 | US Government Resource |
Track CVE-2018-19322 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-19322), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.