PoC Index

CVE-2018-19323

KEV RANSOMWARECRITICAL 9.8EPSS 7.8%

The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes functionality to read and write Machine Specific Registers (MSRs).

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
9.0 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:C
EPSS
7.83% chance of exploitation in the next 30 days, 94th percentile
CISA KEV
added 2022-10-24, used in ransomware campaigns
Published
2018-12-21
Updated
2026-08-13

Proof-of-concept exploits (4)

References

Related