{"id":"CVE-2018-19320","title":"The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes ring0 memcpy-like functionality that could allow a local attacker to…","summary":"The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes ring0 memcpy-like functionality that could allow a local attacker to…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","vendor":"gigabyte","product":"aorus_graphics_engine","affected":["aorus_graphics_engine < 1.57","app_center < 19.0422.1","oc_guru_ii = 2.08","xtreme_gaming_engine < 1.26"],"patched":["aorus_graphics_engine 1.57","app_center 19.0422.1","xtreme_gaming_engine 1.26"],"published":"2018-12-21","updated":"2026-08-13","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2018-19320","references":[{"url":"http://seclists.org/fulldisclosure/2018/Dec/39","label":"cve@mitre.org"},{"url":"http://www.securityfocus.com/bid/106252","label":"cve@mitre.org"},{"url":"https://www.gigabyte.com/Support/Security/1801","label":"cve@mitre.org"},{"url":"https://www.gigabyte.com/tw/Support/Utility/Graphics-Card","label":"cve@mitre.org"},{"url":"https://www.secureauth.com/labs/advisories/gigabyte-drivers-elevation-privilege-vulnerabilities","label":"cve@mitre.org"},{"url":"http://seclists.org/fulldisclosure/2018/Dec/39","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securityfocus.com/bid/106252","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.gigabyte.com/Support/Security/1801","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.gigabyte.com/tw/Support/Utility/Graphics-Card","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.secureauth.com/labs/advisories/gigabyte-drivers-elevation-privilege-vulnerabilities","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-19320","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild","exploit-available"],"epss":0.03597,"epssPercentile":0.88943,"kev":true,"kevDateAdded":"2022-10-24","kevDueDate":"2022-11-14","kevRansomware":true,"exploited":true,"ingestedAt":"2026-08-13T06:00:54.456Z","exploits":{"github":3,"githubRepos":["https://github.com/ASkyeye/CVE-2018-19320","https://github.com/hmnthabit/CVE-2018-19320-LPE","https://github.com/zer0condition/GDRVLoader"],"checkedAt":"2026-09-21T15:23:38.189Z"},"exploitAvailable":true,"slug":"CVE-2018-19320","body":"## Overview\n\nThe GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes ring0 memcpy-like functionality that could allow a local attacker to take complete control of the affected system.\n\n## Affected\n\n- `aorus_graphics_engine < 1.57`\n- `app_center < 19.0422.1`\n- `oc_guru_ii = 2.08`\n- `xtreme_gaming_engine < 1.26`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `aorus_graphics_engine 1.57`\n- `app_center 19.0422.1`\n- `xtreme_gaming_engine 1.26`","depth":"abyssal","depthScore":74,"depthScoreParts":{"impact":42.9,"likelihood":0.7,"exploitation":25,"ransomware":5},"changes":[{"seq":4444,"id":"CVE-2018-19320","ts":1788887180647,"field":"exploit_available","old":"false","new":"true"},{"seq":3327,"id":"CVE-2018-19320","ts":1788886299636,"field":"exploit_available","old":"true","new":"false"},{"seq":2182,"id":"CVE-2018-19320","ts":1788882969355,"field":"exploit_available","old":"false","new":"true"},{"seq":1211,"id":"CVE-2018-19320","ts":1788882373368,"field":"exploit_available","old":"true","new":"false"},{"seq":325,"id":"CVE-2018-19320","ts":1788881815656,"field":"exploit_available","old":"false","new":"true"}]}