← Back to browse · API

CVE-2018-19322

Severity
HIGH
CVSS
7.8
EPSS
0.01872
Risk score
56.86
CISA KEV
Yes
PoC
No
Published
2022-10-24
Modified
2022-10-24
First seen
2026-08-07
Aliases
EUVD-2018-11020, GHSA-VV86-WHXX-RV84
Products
GIGABYTE:Multiple Products, n/a:n/a n/a
Sources
euvd EUVD-2018-11020
cisa.gov CVE-2018-19322

Description

The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated privileges.

References