← Back to browse · API

CVE-2018-19321

Severity
HIGH
CVSS
7.8
EPSS
0.03671
Risk score
57.48
CISA KEV
Yes
PoC
No
Published
2022-10-24
Modified
2022-10-24
First seen
2026-08-07
Aliases
EUVD-2018-11019, GHSA-V6M4-3GV6-Q4JX
Products
GIGABYTE:Multiple Products, n/a:n/a n/a
Sources
euvd EUVD-2018-11019
cisa.gov CVE-2018-19321

Description

The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.

References