Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2018-19320

Description

The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes ring0 memcpy-like functionality that could allow a local attacker to take complete control of the affected system.

POC

Reference

- http://seclists.org/fulldisclosure/2018/Dec/39

- https://www.secureauth.com/labs/advisories/gigabyte-drivers-elevation-privilege-vulnerabilities

Github

- https://github.com/0xT11/CVE-POC

- https://github.com/474172261/KDU

- https://github.com/ARPSyndicate/cvemon

- https://github.com/ASkyeye/CVE-2018-19320

- https://github.com/Adoew/RobbinHood-attack

- https://github.com/BKreisel/CVE-2018-1932X

- https://github.com/BlackTom900131/awesome-game-security

- https://github.com/CVEDB/awesome-cve-repo

- https://github.com/CVEDB/top

- https://github.com/GhostTroops/TOP

- https://github.com/Laud22/Win32_Offensive_Cheatsheet

- https://github.com/Ostorlab/KEV

- https://github.com/Ostorlab/known_exploited_vulnerbilities_detectors

- https://github.com/cmd-theo/RobbinHood-attack

- https://github.com/cygnosic/Gigabyte_Disable_DSE

- https://github.com/gmh5225/RobbinHood-attack

- https://github.com/gmh5225/awesome-game-security

- https://github.com/h4rmy/KDU

- https://github.com/hfiref0x/KDU

- https://github.com/hmnthabit/CVE-2018-19320-LPE

- https://github.com/houseofxyz/CVE-2018-19320

- https://github.com/matthieu-hackwitharts/Win32_Offensive_Cheatsheet

- https://github.com/n0-traces/cve_monitor

- https://github.com/nanaroam/kaditaroam

- https://github.com/robertfischman/game-security

- https://github.com/sl4v3k/KDU

- https://github.com/ss256100/CVE-2018-19320

- https://github.com/thebringerofdeath789/KernelModeCpp

- https://github.com/trevor0106/game-security

- https://github.com/xct/windows-kernel-exploits

- https://github.com/zeon1045/belbel

- https://github.com/zeon1045/intentohibri

- https://github.com/zer0condition/GDRVLoader