Cyber Resilience

CVE-2018-19320

Gigabyte Aorus Graphics Engine ≤ 1.57

CISA KEVActive ExploitationEUVD ExploitedPublic PoCRansomware-linked
Published
21 December 2018
Modified
13 August 2026
KEV Added
24 October 2022
Patch / advisory
CVSS Score v3.1 7.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.036 88th percentile
Risk Priority 83 floored blend · peak EPSS

Summary

CVE-2018-19320 is a high-severity an unspecified weakness vulnerability in Gigabyte Aorus Graphics Engine. Its CVSS base score is 7.8 (High).

Operationally, ranked in the top 12% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog; a public proof-of-concept is referenced.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

The vulnerability affects the GDrv low-level driver shipped with GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before version 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08. It exposes ring-0 memcpy-like functionality that can be invoked directly from user mode, granting arbitrary kernel-memory read and write primitives on the affected Windows systems.

A local attacker with low privileges can load or communicate with the driver to abuse these primitives, achieving arbitrary code execution at ring 0 and thereby obtaining complete control of the system, including the ability to disable security controls, read or modify any process, and persist across reboots. The issue carries a CVSS 3.1 base score of 7.8 and requires no user interaction beyond the ability to execute code in the context of an authenticated local user.

Gigabyte published security advisory 1801 along with updated driver packages on its support site; the SecureAuth Labs advisory and the full-disclosure posting on Seclists provide additional technical detail and proof-of-concept references for verifying remediation status.

EU & UK References

Vulnerability Data

The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes ring0 memcpy-like functionality that could allow a local attacker to take complete control…

more

of the affected system.

CWE(s)
KEV Date Added
24 October 2022

Related Threats

CVEs Like This One

CVE-2018-19322Same product: Gigabyte Aorus Graphics Engineboth on KEV
CVE-2018-19321Same product: Gigabyte Aorus Graphics Engineboth on KEV
CVE-2018-19323Same product: Gigabyte Aorus Graphics Engineboth on KEV
CVE-2026-4415Same vendor: Gigabyte
CVE-2026-4416Same vendor: Gigabyte

Affected Assets

gigabyte
aorus graphics engine
≤ 1.57
gigabyte
app center
≤ 19.0422.1
gigabyte
oc guru ii
2.08
gigabyte
xtreme gaming engine
≤ 1.26

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References