CVE-2019-7630: Critical severity gigabyte app center vulnerability
An issue was discovered in gdrv.sys in Gigabyte APP Center before 19.0227.1. The vulnerable driver exposes a wrmsr instruction via IOCTL 0xC3502580 and does not properly filter the target Model Specific Register (MSR). Allowing arbitrary MSR writes can lead to Ring-0 code execution and escalation of privileges.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2019-7630?
CVE-2019-7630 has a high severity rating due to its potential to allow arbitrary code execution in Ring-0.
How do I fix CVE-2019-7630?
To fix CVE-2019-7630, update the Gigabyte APP Center to version 19.0227.1 or later.
What systems are affected by CVE-2019-7630?
CVE-2019-7630 affects Gigabyte APP Center versions prior to 19.0227.1.
What type of vulnerability is CVE-2019-7630?
CVE-2019-7630 is a driver vulnerability that allows improper handling of Model Specific Registers (MSRs).
What could be the impact of exploiting CVE-2019-7630?
Exploiting CVE-2019-7630 could lead to full system compromise with elevated privileges.