Gigabyte Control Center Software Vulnerability Exposed Kernel Drivers

A newly disclosed security flaw in Gigabyte's Control Center software could allow local attackers to gain kernel-level privileges.

Sep 22, 2026
Industry & Business
Gigabyte Control Center Software Vulnerability Exposed Kernel Drivers

Gigabyte has acknowledged a security vulnerability affecting its Control Center (GCC) software, which could permit local attackers to elevate their privileges to the kernel level (Ring 0). The issue stems from vulnerabilities in two kernel drivers, GVCIDrv64.sys and gdrv3.sys, which are components of the GCC software commonly used with Gigabyte motherboards.

According to Gigabyte, the vulnerabilities reside within the kernel drivers' IOCTL interfaces. These issues arise from insufficient access control and improper validation of input parameters, enabling authenticated local attackers to perform unauthorized operations. These operations include arbitrary physical memory mapping and direct hardware access, potentially leading to a complete system compromise.

An attacker could exploit these vulnerabilities by sending a specially crafted IOCTL request. This would allow them to bypass memory protections and gain the highest level of system access. Gigabyte has credited Mohamed Alzhrani (0xMaz) and Subhan Sultanov (me1n) for discovering the flaws and assisting in the patching process.

A fix is available, with any version of GCC from 26.08.28.01 or later, and GBT_VGA_26.08.24.01 or later, including the mitigation. The current GCC version is 26.09.10.01. The mitigation measures include enhanced access control with strict security descriptors, interface hardening by removing high-risk interfaces, privilege validation for hardware-access functions, and rigorous input validation for all IOCTL parameters.

Users with Gigabyte motherboards are advised to update their Gigabyte Control Center software to the latest version to address these security concerns. Gigabyte maintains a page for its security disclosures where users can find further information.

Sources