Elevated Privilege Vulnerability in GIGABYTE APP Center and Graphics Engines
CVE-2018-19323
Key Information:
- Vendor
Gigabyte
- Vendor
- CVE Published:
- 21 December 2018
Badges
What is CVE-2018-19323?
The GDrv low-level driver within GIGABYTE APP Center and several related graphics engine tools has a vulnerability that allows unauthorized access to read and write Machine Specific Registers (MSRs). This could potentially lead to unauthorized elevation of privileges on affected systems, putting user data and system integrity at risk. Users are advised to update to the latest versions to mitigate potential exploitation.
CISA has reported CVE-2018-19323
CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2018-19323 as being exploited and is known by the CISA as enabling ransomware campaigns.
The CISA's recommendation is: Apply updates per vendor instructions.
References
EPSS Score
23% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- 💰
Used in Ransomware
- 👾
Exploit known to exist
- 🦅
CISA Reported
Vulnerability published
Vulnerability Reserved