CVE-2018-19323

critical

Description

The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes functionality to read and write Machine Specific Registers (MSRs).

References

https://www.secureauth.com/labs/advisories/gigabyte-drivers-elevation-privilege-vulnerabilities

https://www.gigabyte.com/tw/Support/Utility/Graphics-Card

https://www.gigabyte.com/Support/Security/1801

https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-19323

http://www.securityfocus.com/bid/106252

http://seclists.org/fulldisclosure/2018/Dec/39

Details

Source: Mitre, NVD

Published: 2018-12-21

Updated: 2025-10-22

Known Exploited Vulnerability (KEV)

Risk Information

CVSS v2

Base Score: 9

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:C

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.14638