PT-2020-11248 · Gigabyte · Gigabyte App Center

·

CVE-2019-7630

·

Published

2020-03-25

·

Updated

2023-02-03

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Gigabyte APP Center version 19.0227.1 and earlier
Description An issue was discovered in the gdrv.sys driver. The vulnerable driver exposes a wrmsr instruction via IOCTL 0xC3502580 and does not properly filter the target Model Specific Register (MSR). Allowing arbitrary MSR writes can lead to Ring-0 code execution and escalation of privileges.
Recommendations For Gigabyte APP Center version 19.0227.1 and earlier, update to version 19.0227.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the IOCTL 0xC3502580 to minimize the risk of exploitation.

Exploit

Fix

Improper Initialization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-7630

Affected Products

Gigabyte App Center