Skip to content
Gigabyte Control Center Software Vulnerabilities Expose Kernel to Local Attacks

Gigabyte Control Center Software Vulnerabilities Expose Kernel to Local Attacks

First seen 22 Sep 2026, 16:29 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 22, 2026 at 17:34 UTC
  • Multiple vulnerabilities in Gigabyte Control Center software allow local privilege escalation.
  • Affected drivers include GVCIDrv64.sys and gdrv3.sys, requiring immediate software updates.
  • The vulnerabilities are not exploitable remotely, limiting the risk to local attackers only.

Gigabyte has acknowledged multiple vulnerabilities in its Control Center software affecting GIGABYTE motherboards. The vulnerabilities exist in the kernel drivers GVCIDrv64.sys and gdrv3.sys, allowing local attackers to elevate privileges to the kernel level, potentially leading to complete system compromise. The flaws arise from insufficient access control and improper validation of input parameters in the IOCTL interfaces. While the risk of exploitation is limited to local attackers, Gigabyte has released a patch in version 26.08.28.01 and later to mitigate these issues. Security researchers Mohamed Alzhrani (0xMaz) and Subhan Sultanov (me1n) were credited for their role in identifying and addressing the vulnerabilities. Users are strongly advised to update their software to the latest version to ensure protection against these vulnerabilities.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-22
Gigabyte discloses vulnerabilities
Gigabyte announces vulnerabilities in Control Center software affecting kernel drivers, urging users to update.
PC Gamer
2026-09-22
Patch released
Gigabyte releases version 26.08.28.01 of Control Center software to address the vulnerabilities.
TweakTown

More articles in this cluster (2)

Following this threat?

Track Gigabyte in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed