Privilege escalation in GIGABYTE Global products - CVE-2018-19320
Published: December 19, 2018 / Updated: December 27, 2023
Vulnerability identifier: #VU16621
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-19320
CWE-ID: CWE-782
Exploitation vector: Local access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a local unauthenticated attacker to gain elevated privileges on the target device.
The weakness exists due to ring0 memcpy-like functionality built into GIO's IOCTL 0xC3502808. A local attacker can gain elevated privileges.
Affected software
AORUS GRAPHICS ENGINE
GIGABYTE APP Center
XTREME GAMING ENGINE
OC GURU
GIGABYTE APP Center
XTREME GAMING ENGINE
OC GURU
How to mitigate CVE-2018-19320
Cybersecurity Help is currently unaware of any official solution addressing the vulnerability.
Links to Public Exploits and PoC-codes
- Exploit #9463 - CVE-2018-19320 (GIGABYTE Driver exploit Win10 19H1 and 22H2) (December 27, 2023)
- Exploit #8185 - CVE-2018-19320-LPE (CVE-2018-19320 LPE Exploit) (July 26, 2022)
- Exploit #6640 - CVE-2018-19320-LPE (CVE-2018-19320 LPE Exploit) (August 19, 2021)
- Exploit #5333 - CVE-2018-19320 (Exploit for CVE-2018-19320) (May 3, 2021)
- Exploit #5053 - CVE-2018-19320 (Exploiting ring0 memcpy-like functionality to disable Driver Signing Enforcement (DSE)) (January 21, 2021)
- Exploit #2584 - CVE-2018-19320 (Exploiting ring0 memcpy-like functionality to disable Driver Signing Enforcement (DSE)) (April 19, 2020)