Înapoi

Security Advisory — Arbitrary Physical Memory and I/O Port Access Vulnerability in GIGABYTE Control Center Kernel Driver

CVE-2026-XXXXX (Pending)
Sep 21, 2026

GIGABYTE Technology Co., Ltd. acknowledges multiple security vulnerabilities in the GVCIDrv64.sys and gdrv3.sys kernel drivers, components of the GIGABYTE Control Center (GCC) software. We are committed to providing secure and reliable products and have actively addressed these issues to protect our customers.

Vulnerability Details

  • CVE Identifier: CVE-2026-XXXXX (Pending)
  • CVSS Score: 8.8 (High) 3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
  • Vulnerability Type: CWE-782: Exposed IOCTL with Insufficient Access Control.
  • Root Cause: The vulnerabilities exist in the kernel drivers' IOCTL interfaces. Due to insufficient access control and improper validation of input parameters, authenticated local attackers can perform unauthorized operations, including arbitrary physical memory mapping and direct hardware access.

Attack Scenario

An authenticated local attacker can interact with the affected drivers by sending specially crafted IOCTL requests. By exploiting these flaws, the attacker can bypass operating system memory protections, access sensitive physical memory regions, and overwrite kernel process tokens.

Potential Impact

These vulnerabilities allow a local malicious actor to elevate privileges to the kernel level (Ring 0), potentially leading to Local Privilege Escalation (LPE) and complete system compromise (achieving NT AUTHORITY\SYSTEM).

  • Affected Products and SoftwareProduct Name: GIGABYTE Control Center (GCC).
  • Affected Components: GVCIDrv64.sys and gdrv3.sys kernel drivers.
  • Affected Versions: GIGABYTE Control Center v26.03.31.01 and prior versions.


Resolution and Recommended Actions

GIGABYTE has released a software update to rectify the driver's security flaws. The remediation includes the following enhancements:

  1. Enhanced Access Control: Implemented strict security descriptors to ensure that the driver device objects are only accessible to authorized system accounts, preventing unprivileged users from interacting with the driver.
  2. Interface Hardening: Removed unnecessary and high-risk interfaces that allowed direct physical memory mapping.
  3. Privilege Validation: Integrated mandatory privilege checks for all hardware-access functions to ensure only requests with appropriate administrative rights are processed.
  4. Input Validation: Implemented rigorous validation for all IOCTL input parameters to block access to restricted hardware registers and configuration spaces.

  • Mitigation Version: GIGABYTE Control Center_26.08.28.01, GBT_VGA_26.08.24.01 or later.
  • Recommended Action: Customers are strongly advised to upgrade to the latest GCC version immediately.
  • Download Instructions: Please navigate to the Support section of the relevant product page or update via GCC LiveUpdate to download the latest software.


Acknowledgement

We extend our sincere gratitude to Mohamed Alzhrani (0xMaz) and Subhan Sultanov (me1n) for discovering and responsibly reporting these vulnerabilities. Their collaboration has been invaluable in developing a swift and effective response.

 

The release schedule and package contents may be adjusted without further notification. Please check the official support page for the latest updates.

For any further assistance regarding this issue please contact your sales representative, or create a new support ticket at https://esupport.gigabyte.com