CVE-2018-19323
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- November 16, 2018
- Published Date
- December 21, 2018
- Last Updated
- February 04, 2025
- Vendor
- GIGABYTE
- Product
- APP Center, AORUS GRAPHICS ENGINE, XTREME GAMING ENGINE, OC GURU II
- Description
- The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes functionality to read and write Machine Specific Registers (MSRs).
- Tags
- Exploitation
- active
- Automatable
- Yes
- Technical Impact
- total
cisa
malware
ransomware
CVSS Scores
CVSS v3.1
9.8 - CRITICAL
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
9.0
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:C
SSVC Information
References
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2022-10-24 00:00:00 UTC |
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Exploit Used in Malware
-
Added to KEVIntel