CVE-2018-19323: GIGABYTE Multiple Products Privilege Escalation Vulnerability
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes functionality to read and write Machine Specific Registers (MSRs).
Other sources
The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-19323?
CVE-2018-19323 is classified as a high-severity vulnerability due to its potential impact on system security.
How do I fix CVE-2018-19323?
To resolve CVE-2018-19323, update to the latest versions of the affected GIGABYTE software, including GIGABYTE APP Center, AORUS GRAPHICS ENGINE, and OC GURU II.
What products are affected by CVE-2018-19323?
CVE-2018-19323 affects multiple GIGABYTE products, including GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE versions before 1.57, and OC GURU II v2.08.
What is the risk associated with CVE-2018-19323?
The risk associated with CVE-2018-19323 includes unauthorized access to sensitive system resources through the manipulation of Machine Specific Registers.
Is there a workaround for CVE-2018-19323 if I cannot update immediately?
There is no documented workaround for CVE-2018-19323; updating to the latest version is the recommended solution.