← Vulnerability feed

Vulnerability record · CVE-2018-19323 · published 21 December 2018

CVE-2018-19323: GIGABYTE GDrv driver exposes MSR read/write for privilege escalation

Gigabyte · Aorus Graphics Engine

The GDrv low-level driver shipped with GIGABYTE APP Center, AORUS GRAPHICS ENGINE, XTREME GAMING ENGINE and OC GURU II exposes functionality that lets callers read and write Machine Specific Registers (MSRs). Because MSRs control privileged CPU state, this interface gives a path from user mode to kernel-level control on affected Windows hosts. The record does not specify the exact vulnerable driver version or the precise access control weakness.

9.8 CVSS 3.1 Critical CISA KEV since 24 Oct 2022 Known ransomware use EPSS 7.8% · top 5.5%
9.8CVSS 3.1 base score, v2 9.0
7.8%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
4Affected product versions listed by NVD
11References, 4 tagged exploit
13 Aug 2026Last modified by NVD

Description

The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes functionality to read and write Machine Specific Registers (MSRs).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

critical priorityCVSS 9.8, CISA KEV listing with known ransomware use, and a driver-level privilege escalation path make this a top remediation priority despite the thin technical description.

What it is

The GDrv low-level driver shipped with GIGABYTE APP Center, AORUS GRAPHICS ENGINE, XTREME GAMING ENGINE and OC GURU II exposes functionality that lets callers read and write Machine Specific Registers (MSRs). Because MSRs control privileged CPU state, this interface gives a path from user mode to kernel-level control on affected Windows hosts. The record does not specify the exact vulnerable driver version or the precise access control weakness.

Impact

An attacker who can reach the driver interface gains the ability to read and write MSRs, which can be used to escalate privileges to kernel level and to tamper with CPU configuration. CISA lists known ransomware campaign use, so the practical outcome is full host compromise.

Attack surface

The flaw is in a locally installed driver, so it is reached from software running on the host rather than over the network; the CVSS vector is AV:N/PR:N/UI:N, but the description gives no network-facing service, so treat the vector as inconsistent with the local driver nature. No authentication or user interaction is described as required.

Exploitation

CISA added it to KEV on 2022-10-24 with known ransomware campaign use, and public exploit references exist in the advisory and mailing-list links. EPSS is 0.07828 (94th percentile), indicating elevated but not top-tier predicted activity.

What to do

  • Apply the vendor updates referenced in GIGABYTE's security advisory (https://www.gigabyte.com/Support/Security/1801) and upgrade or remove the affected utilities.
  • Remove or disable GIGABYTE APP Center, AORUS GRAPHICS ENGINE, XTREME GAMING ENGINE and OC GURU II on systems that do not require them.
  • Block loading of the vulnerable GDrv driver via Windows driver blocklist or application control policy where the utilities are not needed.
  • Restrict local administrator rights and monitor for unexpected driver installation or service creation on endpoints.
  • Treat any host with these utilities as potentially compromised and hunt for post-exploitation activity given the KEV ransomware association.

Detection

  • Search endpoint inventories for the affected GIGABYTE utilities and the GDrv driver file or service.
  • Monitor for driver load events and service creation involving GDrv or GIGABYTE utility paths.
  • Alert on processes making unusual MSR-related driver IOCTLs or on unsigned/known-vulnerable driver loads.
  • Correlate KEV-listed exploitation with ransomware precursor behavior such as credential access and lateral movement on hosts running these utilities.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2018-19323 to the Known Exploited Vulnerabilities catalog on 24 October 2022 as "GIGABYTE Multiple Products Privilege Escalation Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 14 November 2022.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-19323 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2018-19323), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.