---
id: CVE-2018-19322
title: >-
  The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and
  earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26,
  and OC GURU II v2.08 expose functionality to read/write data from/to IO ports
summary: >-
  The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and
  earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26,
  and OC GURU II v2.08 expose functionality to read/write data from/to IO ports.
  This …
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-749
vendor: gigabyte
product: aorus_graphics_engine
affected:
  - aorus_graphics_engine < 1.57
  - app_center <= 1.05.21
  - oc_guru_ii = 2.08
  - xtreme_gaming_engine < 1.26
patched:
  - aorus_graphics_engine 1.57
  - xtreme_gaming_engine 1.26
published: '2018-12-21'
updated: '2026-08-13'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2018-19322'
references:
  - url: 'http://seclists.org/fulldisclosure/2018/Dec/39'
    label: cve@mitre.org
  - url: 'http://www.securityfocus.com/bid/106252'
    label: cve@mitre.org
  - url: 'https://www.gigabyte.com/Support/Security/1801'
    label: cve@mitre.org
  - url: 'https://www.gigabyte.com/tw/Support/Utility/Graphics-Card'
    label: cve@mitre.org
  - url: >-
      https://www.secureauth.com/labs/advisories/gigabyte-drivers-elevation-privilege-vulnerabilities
    label: cve@mitre.org
  - url: 'http://seclists.org/fulldisclosure/2018/Dec/39'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.securityfocus.com/bid/106252'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.gigabyte.com/Support/Security/1801'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.gigabyte.com/tw/Support/Utility/Graphics-Card'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.secureauth.com/labs/advisories/gigabyte-drivers-elevation-privilege-vulnerabilities
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-19322
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
epss: 0.01801
epssPercentile: 0.77539
kev: true
kevDateAdded: '2022-10-24'
kevDueDate: '2022-11-14'
kevRansomware: true
exploited: true
ingestedAt: '2026-08-13T06:00:54.525Z'
---

## Overview

The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated privileges.

## Affected

- `aorus_graphics_engine < 1.57`
- `app_center <= 1.05.21`
- `oc_guru_ii = 2.08`
- `xtreme_gaming_engine < 1.26`

## Remediation

Upgrade past the affected range:

- `aorus_graphics_engine 1.57`
- `xtreme_gaming_engine 1.26`
