CVE-2018-19323
CRITICAL(9.8)KEV — Aktiv ausgenutztCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CVSS 9.8 — Kritisch
- Im CISA KEV-Katalog (aktiv ausgenutzt)
CISA KEV
Bestätigt ausgenutzt
EPSS-Score
7.8%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
9.8
Technische Schwere
SecBoard-Einordnung
CVE-2018-19323 betrifft den GDrv Low-Level-Treiber in verschiedenen GIGABYTE-Softwareprodukten wie APP Center, AORUS GRAPHICS ENGINE, XTREME GAMING ENGINE und OC GURU II. Die Schwachstelle ermöglicht es, Machine Specific Registers (MSRs) zu lesen und zu schreiben. Dies kann zu einer vollständigen Kompromittierung des Systems führen, da Angreifer potenziell beliebigen Code mit Kernel-Privilegien ausführen könnten.
KI-gestützte Einordnung auf Basis der NVD-Daten.
Beschreibung
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes functionality to read and write Machine Specific Registers (MSRs).
Betroffene Produkte
- cpe:2.3:a:gigabyte:aorus_graphics_engine:*:*:*:*:*:*:*:*
- cpe:2.3:a:gigabyte:gigabyte_app_center:*:*:*:*:*:*:*:*
- cpe:2.3:a:gigabyte:oc_guru_ii:2.08:*:*:*:*:*:*:*
- cpe:2.3:a:gigabyte:xtreme_gaming_engine:*:*:*:*:*:*:*:*
Referenzen
- http://seclists.org/fulldisclosure/2018/Dec/39
- http://www.securityfocus.com/bid/106252
- https://www.gigabyte.com/Support/Security/1801
- https://www.gigabyte.com/tw/Support/Utility/Graphics-Card
- https://www.secureauth.com/labs/advisories/gigabyte-drivers-elevation-privilege-...
- http://seclists.org/fulldisclosure/2018/Dec/39
- http://www.securityfocus.com/bid/106252
- https://www.gigabyte.com/Support/Security/1801
- https://www.gigabyte.com/tw/Support/Utility/Graphics-Card
- https://www.secureauth.com/labs/advisories/gigabyte-drivers-elevation-privilege-...