7.8 CVE-2018-19320

CISA Kev Catalog Used by Malware Used by Ransomware Exploit
 

The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes ring0 memcpy-like functionality that could allow a local attacker to take complete control of the affected system.
https://nvd.nist.gov/vuln/detail/CVE-2018-19320

Categories

CWE-NVD-noinfo

References


 

CPE

cpe start end
Configuration 1
cpe:2.3:a:gigabyte:aorus_graphics_engine:*:*:*:*:*:*:*:* < 1.57
cpe:2.3:a:gigabyte:app_center:*:*:*:*:*:*:*:* < 19.0422.1
cpe:2.3:a:gigabyte:oc_guru_ii:2.08:*:*:*:*:*:*:*
cpe:2.3:a:gigabyte:xtreme_gaming_engine:*:*:*:*:*:*:*:* < 1.26


REMEDIATION




EXPLOITS


Exploit-db.com

id description date
No known exploits

POC Github

Url
No known exploits

Other Nist (github, ...)

Url
http://seclists.org/fulldisclosure/2018/Dec/39
https://www.secureauth.com/labs/advisories/gigabyte-drivers-elevation-privile...


CAPEC


Common Attack Pattern Enumerations and Classifications

id description severity
No entry