Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Nov 14, 2022

CVE-2018-19320

High
EPSS 38.7%CISA KEVRansomware
GIGABYTE/Multiple Products

Description

The GDrv low-level driver in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II exposes ring0 memcpy-like functionality that could allow a local attacker to take complete control of the affected system.

EPSS — Exploit Probability

38.7%

Higher than 97.2% of all CVEs

Required Action

https://www.gigabyte.com/Support/Security/1801; https://nvd.nist.gov/vuln/detail/CVE-2018-19320

Risk Assessment

HIGH
In CISA KEV
Ransomware

Details

Severity
High
EPSS
38.7%
CISA KEV
Yes
Ransomware
Known
Articles
0

Timeline

Published

Oct 24, 2022

Added to KEV

Oct 24, 2022

Remediation Due

Nov 14, 2022

Affected Product

GIGABYTE

Multiple Products

View all GIGABYTE CVEs