← Vulnerability feed

Vulnerability record · CVE-2018-19322 · published 21 December 2018

CVE-2018-19322: GIGABYTE driver IO port access allows privilege escalation

Gigabyte · Aorus Graphics Engine

The GPCIDrv and GDrv low-level drivers shipped with GIGABYTE APP Center, AORUS GRAPHICS ENGINE, XTREME GAMING ENGINE and OC GURU II expose IO port read/write functionality to user-mode callers. Because this primitive is not properly restricted, an attacker can abuse it to run code with elevated privileges. The flaw affects multiple widely installed GIGABYTE utilities, so it is relevant to any endpoint with those tools present.

7.8 CVSS 3.1 High CISA KEV since 24 Oct 2022 Known ransomware use EPSS 1.8% · top 22.4% CWE-749 · CWE-749
7.8CVSS 3.1 base score, v2 4.6
1.8%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
4Affected product versions listed by NVD
11References, 4 tagged exploit
13 Aug 2026Last modified by NVD

Description

The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated privileges.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityThe vulnerability is in CISA KEV with known ransomware use and allows local privilege escalation to full system control, though it requires local access and low privileges to trigger.

What it is

The GPCIDrv and GDrv low-level drivers shipped with GIGABYTE APP Center, AORUS GRAPHICS ENGINE, XTREME GAMING ENGINE and OC GURU II expose IO port read/write functionality to user-mode callers. Because this primitive is not properly restricted, an attacker can abuse it to run code with elevated privileges. The flaw affects multiple widely installed GIGABYTE utilities, so it is relevant to any endpoint with those tools present.

Impact

An attacker who can execute code on the host gains kernel-level or SYSTEM privileges, enabling full control of the machine, persistence and disabling of security controls.

Attack surface

Reached locally through the vulnerable driver interface; the CVSS vector indicates low privileges are required and no user interaction is needed. No remote or network vector is described.

Exploitation

CVE-2018-19322 is listed in CISA KEV with a due date of 2022-11-14 and is flagged for known ransomware campaign use; EPSS 30-day probability is about 1.8 percent (77th percentile). Public exploit references exist in the advisory and mailing list entries.

What to do

  • Apply the vendor updates referenced in GIGABYTE's security advisory (https://www.gigabyte.com/Support/Security/1801) and upgrade the affected utilities to fixed versions.
  • If patching is not immediately possible, remove or disable the GIGABYTE APP Center, AORUS GRAPHICS ENGINE, XTREME GAMING ENGINE and OC GURU II software and their drivers from endpoints that do not require them.
  • Restrict local administrative rights and monitor for non-admin processes loading GPCIDrv or GDrv.
  • Block or alert on driver load events for the affected driver files via application control or WDAC policies.

Detection

  • Hunt for driver load events (Sysmon Event ID 6) referencing GPCIDrv or GDrv, especially from non-standard or user-writable paths.
  • Monitor for processes that load the vulnerable drivers and subsequently perform privileged operations or spawn elevated children.
  • Alert on creation or modification of the affected GIGABYTE utility binaries and drivers on endpoints.
  • Review endpoint inventory for installations of APP Center, AORUS GRAPHICS ENGINE, XTREME GAMING ENGINE and OC GURU II to scope exposure.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2018-19322 to the Known Exploited Vulnerabilities catalog on 24 October 2022 as "GIGABYTE Multiple Products Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 14 November 2022.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-19322 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-19323GIGABYTE GDrv driver exposes MSR read/write for privilege escalationThe GDrv low-level driver shipped with GIGABYTE APP Center, AORUS GRAPHICS ENGINE, XTREME GAMING ENGINE and OC GURU II exposes functionality that let…KEVEPSS 7.8%analysed7.8CVE-2018-19320GIGABYTE GDrv driver exposes ring0 memory write to local attackersThe GDrv low-level driver shipped with GIGABYTE APP Center, AORUS GRAPHICS ENGINE, XTREME GAMING ENGINE and OC GURU II exposes memcpy-like functional…KEVEPSS 3.6%analysed7.8CVE-2018-19321GIGABYTE driver exposes arbitrary physical memory read/writeThe GPCIDrv and GDrv low-level drivers shipped with GIGABYTE APP Center (v1.05.21 and earlier), AORUS GRAPHICS ENGINE (before 1.57), XTREME GAMING EN…KEVEPSS 3.7%analysed7.2CVE-2019-7630Gigabyte app center vulnerabilityAn issue was discovered in gdrv.sys in Gigabyte APP Center before 19.0227.1. The vulnerable driver exposes a wrmsr instruction via IOCTL 0xC3502580 a…EPSS 3.1%7.5CVE-2010-1428JBoss EAP Web Console access control bypass via non-GET/POST methodsThe Web Console in JBoss Enterprise Application Platform enforces access control only for GET and POST requests, so any other HTTP method bypasses th…KEVEPSS 62%analysed5.3CVE-2010-0738JBoss JMX-Console access control bypass via non-GET/POST HTTP methodsThe JMX-Console web application in Red Hat JBoss EAP 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 enforces access control only for GET and POST re…KEVEPSS 79%analysed7.5CVE-2006-1547Apache Struts 1 ActionForm multipart parameter denial of serviceApache Struts before 1.2.9 with BeanUtils 1.7 exposes the public getMultipartRequestHandler method through ActionForm parameter binding. A remote att…KEVEPSS 55%analysed

Source: NIST National Vulnerability Database (record CVE-2018-19322), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.