← Vulnerability feed

Vulnerability record · CVE-2019-7630 · published 25 March 2020

CVE-2019-7630: Gigabyte app center vulnerability

Gigabyte · App Center

An issue was discovered in gdrv.sys in Gigabyte APP Center before 19.0227.1. The vulnerable driver exposes a wrmsr instruction via IOCTL 0xC3502580 and does not properly filter the target Model Specific Register (MSR). Allowing arbitrary MSR writes can lead to Ring-0 code execution and escalation of privileges.

7.2 CVSS 3.1 High EPSS 3.1% · top 12.8% CWE-665 · CWE-665
7.2CVSS 3.1 base score, v2 9.0
3.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered in gdrv.sys in Gigabyte APP Center before 19.0227.1. The vulnerable driver exposes a wrmsr instruction via IOCTL 0xC3502580 and does not properly filter the target Model Specific Register (MSR). Allowing arbitrary MSR writes can lead to Ring-0 code execution and escalation of privileges.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-7630 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2018-19320GIGABYTE GDrv driver exposes ring0 memory write to local attackersThe GDrv low-level driver shipped with GIGABYTE APP Center, AORUS GRAPHICS ENGINE, XTREME GAMING ENGINE and OC GURU II exposes memcpy-like functional…KEVEPSS 3.6%analysed7.8CVE-2018-19321GIGABYTE driver exposes arbitrary physical memory read/writeThe GPCIDrv and GDrv low-level drivers shipped with GIGABYTE APP Center (v1.05.21 and earlier), AORUS GRAPHICS ENGINE (before 1.57), XTREME GAMING EN…KEVEPSS 3.7%analysed7.8CVE-2018-19322GIGABYTE driver IO port access allows privilege escalationThe GPCIDrv and GDrv low-level drivers shipped with GIGABYTE APP Center, AORUS GRAPHICS ENGINE, XTREME GAMING ENGINE and OC GURU II expose IO port re…KEVEPSS 1.8%analysed7.8CVE-2022-0847Linux kernel pipe buffer flaw allows local privilege escalationThe flags member of the new pipe buffer structure was not properly initialized in copy_page_to_iter_pipe and push_pipe, so it could hold stale values…KEVEPSS 93%analysed6.5CVE-2013-1675Mozilla Firefox and Thunderbird uninitialized memory information disclosureFirefox, Firefox ESR, Thunderbird and Thunderbird ESR fail to properly initialize the nsDOMSVGZoomEvent::mPreviousScale and mNewScale data structures…KEVEPSS 6.7%analysed5.5CVE-2020-27950Apple XNU kernel memory initialization flaw leaks kernel memoryA memory initialization issue in Apple's XNU kernel leaves kernel memory improperly initialized, allowing a malicious application to disclose kernel …KEVEPSS 17%analysed

Source: NIST National Vulnerability Database (record CVE-2019-7630), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.