CVE-2018-19323: GIGABYTE Multiple Products Privilege Escalation Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2022-10-24. EPSS: 8.4% chance of exploitation in the next 30 days.

The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes functionality to read and write Machine Specific Registers (MSRs).

Affected products

  • GIGABYTE Aorus Graphics Engine: before 1.57 (fixed in 1.57)
  • GIGABYTE GIGABYTE App Center: up to and including 1.05.21
  • GIGABYTE Oc Guru Ii: version 2.08 only
  • GIGABYTE Xtreme Gaming Engine: before 1.26 (fixed in 1.26)

Published 2018-12-21. Last modified 2026-10-01.