CVE-2018-19323
KEV
🔴 Łataj teraz
Niewłaściwe zarządzanie rejestrami w GIGABYTE APP Center umożliwia nieautoryzowany dostęp do MSR.
CVSS
9.8
EPSS
8.5%
Exploit
weaponized
Vendor
gigabyte
Opis źródłowy (NVD)
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes functionality to read and write Machine Specific Registers (MSRs).
exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 9.8 |
| CISA KEV (aktywnie wykorzystywane) | Tak |
| FIRST EPSS (prawdopodobieństwo exploita) | 8.5% |
| Opublikowano (NVD) | 2018-12-21 23:29:00 UTC |
| Ostatnia modyfikacja (NVD) | 2026-08-13 05:17:17 UTC |
Referencje
- http://seclists.org/fulldisclosure/2018/Dec/39 (cve@mitre.org) [Exploit, Mailing List, Third Party Advisory]
- http://www.securityfocus.com/bid/106252 (cve@mitre.org) [Broken Link, Third Party Advisory, VDB Entry]
- https://www.gigabyte.com/Support/Security/1801 (cve@mitre.org) [Vendor Advisory]
- https://www.gigabyte.com/tw/Support/Utility/Graphics-Card (cve@mitre.org) [Product]
- https://www.secureauth.com/labs/advisories/gigabyte-drivers-elevation-privilege-vulnerabilities (cve@mitre.org) [Broken Link, Exploit, Third Party Advisory]
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-19323 (134c704f-9b21-4f2e-91b3-4a467353bcc0) [US Government Resource]