High severity7.8CISA KEVNVD Advisory· Published Dec 21, 2018· Updated Aug 13, 2026
CVE-2018-19321
CVE-2018-19321
Description
The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8cpe:2.3:a:gigabyte:aorus_graphics_engine:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:gigabyte:aorus_graphics_engine:*:*:*:*:*:*:*:*range: <1.57
- (no CPE)range: <1.57
cpe:2.3:a:gigabyte:app_center:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:gigabyte:app_center:*:*:*:*:*:*:*:*range: <19.0422.1
- (no CPE)range: <=1.05.21
cpe:2.3:a:gigabyte:oc_guru_ii:2.08:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:gigabyte:oc_guru_ii:2.08:*:*:*:*:*:*:*
- (no CPE)range: =2.08
cpe:2.3:a:gigabyte:xtreme_gaming_engine:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:gigabyte:xtreme_gaming_engine:*:*:*:*:*:*:*:*range: <1.26
- (no CPE)range: <1.26
Patches
Vulnerability mechanics
References
5- seclists.org/fulldisclosure/2018/Dec/39nvdExploitMailing ListThird Party Advisory
- www.secureauth.com/labs/advisories/gigabyte-drivers-elevation-privilege-vulnerabilitiesnvdBroken LinkExploitThird Party Advisory
- www.securityfocus.com/bid/106252nvdBroken LinkThird Party AdvisoryVDB Entry
- www.gigabyte.com/Support/Security/1801nvdVendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
0No linked articles in our index yet.