CVE-2018-19321: GIGABYTE Multiple Products Privilege Escalation Vulnerability
The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.
Other sources
The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-19321?
CVE-2018-19321 has a high severity rating due to its potential for local attackers to exploit memory vulnerabilities.
How do I fix CVE-2018-19321?
To fix CVE-2018-19321, update to the latest versions of GIGABYTE APP Center, AORUS Graphics Engine, XTREME GAMING ENGINE, or OC GURU II as specified in the security advisories.
What systems are affected by CVE-2018-19321?
CVE-2018-19321 affects various GIGABYTE applications, including GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, and XTREME GAMING ENGINE before 1.26.
What type of vulnerability is CVE-2018-19321?
CVE-2018-19321 is a local privilege escalation vulnerability that allows reading and writing of arbitrary physical memory.
Who should be concerned about CVE-2018-19321?
Users and system administrators of affected GIGABYTE products should be concerned about CVE-2018-19321 and take immediate action to mitigate the risk.