target entity

GIGABYTE

4 source-linked records in the current knowledge graph.

high

CVE-2018-19323: GIGABYTE Multiple Products Privilege Escalation Vulnerability

The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges. Required action: Apply updates per vendor instructions.

CVE-2018-19323EPSS 8.5%GIGABYTEMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2018-19322: GIGABYTE Multiple Products Code Execution Vulnerability

The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated privileges. Required action: Apply updates per vendor instructions.

CVE-2018-19322EPSS 1.9%GIGABYTEMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2018-19321: GIGABYTE Multiple Products Privilege Escalation Vulnerability

The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges. Required action: Apply updates per vendor instructions.

CVE-2018-19321EPSS 3.7%GIGABYTEMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2018-19320: GIGABYTE Multiple Products Unspecified Vulnerability

The GDrv low-level driver in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II exposes ring0 memcpy-like functionality that could allow a local attacker to take complete control of the affected system. Required action: Apply updates per vendor instructions.

CVE-2018-19320EPSS 3.6%GIGABYTEMultiple Products
CISA KEV ↗ · unattributed attribution