Urgent.News

What's breaking now, across thousands of outlets.

Tech

Gigabyte admits an oopsie with Gigabyte Control Center software leaving kernel exposed to attackers

Mitigated version is already available.

Gigabyte admits an oopsie with Gigabyte Control Center software leaving kernel exposed to attackers

Gigabyte has released an update for its Control Center software that addresses a vulnerability affecting two kernel drivers, GVCIDrv64.sys and gdrv3.sys. The issue stems from insufficient access control and improper validation of input parameters, allowing authenticated local attackers to perform unauthorized operations such as arbitrary physical memory mapping and direct hardware access. By sending a crafted IOCTL request, an attacker could bypass memory protections and elevate themselves to the kernel level.

The company acknowledges the discovery of the flaw by Mohamed Alzhrani (0xMaz) and Subhan Sultanov (me1n) and thanks them for their assistance in the patching process. Gigabyte warns that this is a period when Intel is rumored to be discontinuing its bug bounty program. Users with GCC versions 26.08.28.01, GBT_VGA_26.08.24.01, or later already have the necessary fix implemented.

The current version is 26.09.10.01. Gigabyte has introduced several measures to address the issue, including enhanced access control, interface hardening, privilege validation, and input validation. To protect systems, users are advised to update their software, as the latest version is 26.09.10.01. For more information, visit Gigabyte's dedicated security disclosure page.

Written by urgent.news from PC Gamer's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at pcgamer.com →

More in Tech

More from Tuesday 22 September →