{"id":"CVE-2018-19322","title":"The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to read/write data from/to IO ports","summary":"The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to read/write data from/to IO ports. This …","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-749"],"vendor":"gigabyte","product":"aorus_graphics_engine","affected":["aorus_graphics_engine < 1.57","app_center <= 1.05.21","oc_guru_ii = 2.08","xtreme_gaming_engine < 1.26"],"patched":["aorus_graphics_engine 1.57","xtreme_gaming_engine 1.26"],"published":"2018-12-21","updated":"2026-08-13","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2018-19322","references":[{"url":"http://seclists.org/fulldisclosure/2018/Dec/39","label":"cve@mitre.org"},{"url":"http://www.securityfocus.com/bid/106252","label":"cve@mitre.org"},{"url":"https://www.gigabyte.com/Support/Security/1801","label":"cve@mitre.org"},{"url":"https://www.gigabyte.com/tw/Support/Utility/Graphics-Card","label":"cve@mitre.org"},{"url":"https://www.secureauth.com/labs/advisories/gigabyte-drivers-elevation-privilege-vulnerabilities","label":"cve@mitre.org"},{"url":"http://seclists.org/fulldisclosure/2018/Dec/39","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securityfocus.com/bid/106252","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.gigabyte.com/Support/Security/1801","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.gigabyte.com/tw/Support/Utility/Graphics-Card","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.secureauth.com/labs/advisories/gigabyte-drivers-elevation-privilege-vulnerabilities","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-19322","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild"],"epss":0.01801,"epssPercentile":0.77203,"kev":true,"kevDateAdded":"2022-10-24","kevDueDate":"2022-11-14","kevRansomware":true,"exploited":true,"ingestedAt":"2026-08-13T06:00:54.525Z","slug":"CVE-2018-19322","body":"## Overview\n\nThe GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated privileges.\n\n## Affected\n\n- `aorus_graphics_engine < 1.57`\n- `app_center <= 1.05.21`\n- `oc_guru_ii = 2.08`\n- `xtreme_gaming_engine < 1.26`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `aorus_graphics_engine 1.57`\n- `xtreme_gaming_engine 1.26`","depth":"abyssal","depthScore":73,"depthScoreParts":{"impact":42.9,"likelihood":0.4,"exploitation":25,"ransomware":5},"changes":[]}