Skip to main content

Multiple Products vulnerabilities

4 published alerts for GIGABYTE Multiple Products.

Actively exploited (KEV)Ransomware

CVE-2018-19323

GIGABYTE Multiple Products Privilege Escalation Vulnerability

GIGABYTE Multiple Products is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-19323). The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges. CISA remediation due date: 2022-11-14. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2018-19322

GIGABYTE Multiple Products Code Execution Vulnerability

GIGABYTE Multiple Products is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-19322). The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated privileges. CISA remediation due date: 2022-11-14. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2018-19321

GIGABYTE Multiple Products Privilege Escalation Vulnerability

GIGABYTE Multiple Products is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-19321). The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges. CISA remediation due date: 2022-11-14. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2018-19320

GIGABYTE Multiple Products Unspecified Vulnerability

GIGABYTE Multiple Products is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-19320). The GDrv low-level driver in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II exposes ring0 memcpy-like functionality that could allow a local attacker to take complete control of the affected system. CISA remediation due date: 2022-11-14. If you need help checking exposure, call (864) 335-9223.