Gigabyte admits an oopsie with Gigabyte Control Center software leaving kernel exposed to attackers

by · PC Gamer

Share this article
0
Join the conversation
Follow us
Add us as a preferred source on Google
Newsletter
Subscribe to our newsletter

Gigabyte

"These vulnerabilities allow a local malicious actor to elevate privileges to the kernel level (Ring 0), potentially leading to Local Privilege Escalation (LPE) and complete system compromise (achieving NT AUTHORITY\SYSTEM)."

If you have a Gigabyte motherboard and use the Gigabyte Control Center (GCC) software, you'd better download the latest version of the software. While the risk of a local attacker hacking into your PC is pretty slim, it's best practice to just cover your butt before anything bad happens.

Gigabyte has listed a new vulnerability on its website that affects a pair of kernel drivers, GVCIDrv64.sys and gdrv3.sys. It says the drivers are components of the GCC software, which is widely recommended alongside the company's motherboards.

"The vulnerabilities exist in the kernel drivers' IOCTL interfaces." Gigabyte says of the cause of the vulnerability. "Due to insufficient access control and improper validation of input parameters, authenticated local attackers can perform unauthorized operations, including arbitrary physical memory mapping and direct hardware access.

Latest Videos FromPC Gamer
Watch full video here:

An attacker can wield those vulnerable drivers through a "specially crafted" IOCTL request. In doing so, bypassing important memory protections and allowing them to elevate themselves to the most trusted level of your PC, the kernel.

Gigabyte thanks Mohamed Alzhrani (0xMaz) and Subhan Sultanov (me1n) for discovering the vulnerability and helping the patching effort. This comes at a time when Intel is said to be ending its lucrative bug bounty program.

There is a fix available. Any version of GCC from 26.08.28.01, GBT_VGA_26.08.24.01 or later has the mitigation in place. Looks like the current GCC version is 26.09.10.01. The mitigation includes the following:

  • Enhanced Access Control: Implemented strict security descriptors to ensure that the driver device objects are only accessible to authorized system accounts, preventing unprivileged users from interacting with the driver.
  • Interface Hardening: Removed unnecessary and high-risk interfaces that allowed direct physical memory mapping.
  • Privilege Validation: Integrated mandatory privilege checks for all hardware-access functions to ensure only requests with appropriate administrative rights are processed.
  • Input Validation: Implemented rigorous validation for all IOCTL input parameters to block access to restricted hardware registers and configuration spaces.

So, get that software updated. And if you're keen to stay on top of these things, here's the Gigabyte page with all its security disclosures.

The biggest gaming news, reviews and hardware deals

Keep up to date with the most important stories and the best deals, as picked by the PC Gamer team.

Contact me with news and offers from other Future brandsReceive email from us on behalf of our trusted partners or sponsors

Best gaming monitors 2026

1. Best overall / 4K:
MSI MPG 322UR X24

2. Best budget 4K:
Asus ROG Strix XG27UCG

3. Best budget OLED
Alienware AW2726DM

4. Best 1440p:
MSI MPG 271QRX

5. Best budget 1440p:
KTC H27T22C-3

6. Best 1080p:
AOC Gaming C27G4ZXE

7. Best Ultrawide:
Gigabyte MO34WQC2

8. Best budget ultrawide:
Koorui 34E6UC

9. Best competitive
KTC 25M1

👉Check out our full gaming monitor guide👈