---
id: CVE-2018-19321
title: >-
  The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and
  earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26,
  and OC GURU II v2.08 expose functionality to read and write arbitrary physical
  memor…
summary: >-
  The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and
  earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26,
  and OC GURU II v2.08 expose functionality to read and write arbitrary physical
  memor…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
vendor: gigabyte
product: aorus_graphics_engine
affected:
  - aorus_graphics_engine < 1.57
  - app_center < 19.0422.1
  - oc_guru_ii = 2.08
  - xtreme_gaming_engine < 1.26
patched:
  - aorus_graphics_engine 1.57
  - app_center 19.0422.1
  - xtreme_gaming_engine 1.26
published: '2018-12-21'
updated: '2026-08-13'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2018-19321'
references:
  - url: 'http://seclists.org/fulldisclosure/2018/Dec/39'
    label: cve@mitre.org
  - url: 'http://www.securityfocus.com/bid/106252'
    label: cve@mitre.org
  - url: 'https://www.gigabyte.com/Support/Security/1801'
    label: cve@mitre.org
  - url: >-
      https://www.secureauth.com/labs/advisories/gigabyte-drivers-elevation-privilege-vulnerabilities
    label: cve@mitre.org
  - url: 'http://seclists.org/fulldisclosure/2018/Dec/39'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.securityfocus.com/bid/106252'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.gigabyte.com/Support/Security/1801'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.secureauth.com/labs/advisories/gigabyte-drivers-elevation-privilege-vulnerabilities
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-19321
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
epss: 0.03671
epssPercentile: 0.89172
kev: true
kevDateAdded: '2022-10-24'
kevDueDate: '2022-11-14'
kevRansomware: true
exploited: true
ingestedAt: '2026-08-13T06:00:54.491Z'
exploits:
  github: 2
  githubRepos:
    - 'https://github.com/nanabingies/Driver-RW'
    - 'https://github.com/nanabingies/CVE-2018-19321'
  checkedAt: '2026-09-24T07:52:46.673Z'
exploitAvailable: true
---

## Overview

The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.

## Affected

- `aorus_graphics_engine < 1.57`
- `app_center < 19.0422.1`
- `oc_guru_ii = 2.08`
- `xtreme_gaming_engine < 1.26`

## Remediation

Upgrade past the affected range:

- `aorus_graphics_engine 1.57`
- `app_center 19.0422.1`
- `xtreme_gaming_engine 1.26`
