Cybersecurity Alerts

Actively Exploited Vulnerabilities

← Back to Cybersecurity Alerts

CVE-2018-19322

GIGABYTE | Multiple ProductsAdded 2022-10-24Remediation Deadline 2022-11-14Active Ransomware Campaign

GIGABYTE Multiple Products Code Execution Vulnerability

The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated privileges.

Required Action

Apply updates per vendor instructions.

Weakness Classification

CWE-749

References