Gigabyte admits an oopsie with Gigabyte Control Center software leaving kernel exposed to attackers

2 hours ago 7
Gigabyte Control Center software (Image credit: Gigabyte)
Gigabyte X870E Aorus Pro motherboard with the SSD heatsinks detached and on a light desk.

"These vulnerabilities allow a local malicious actor to elevate privileges to the kernel level (Ring 0), potentially leading to Local Privilege Escalation (LPE) and complete system compromise (achieving NT AUTHORITY\SYSTEM)."

If you have a Gigabyte motherboard and use the Gigabyte Control Center (GCC) software, you'd better download the latest version of the software. While the risk of a local attacker hacking into your PC is pretty slim, it's best practice to just cover your butt before anything bad happens.

Gigabyte has listed a new vulnerability on its website that affects a pair of kernel drivers, GVCIDrv64.sys and gdrv3.sys. It says the drivers are components of the GCC software, which is widely recommended alongside the company's motherboards.

"The vulnerabilities exist in the kernel drivers' IOCTL interfaces." Gigabyte says of the cause of the vulnerability. "Due to insufficient access control and improper validation of input parameters, authenticated local attackers can perform unauthorized operations, including arbitrary physical memory mapping and direct hardware access.

An attacker can wield those vulnerable drivers through a "specially crafted" IOCTL request. In doing so, bypassing important memory protections and allowing them to elevate themselves to the most trusted level of your PC, the kernel.

Gigabyte thanks Mohamed Alzhrani (0xMaz) and Subhan Sultanov (me1n) for discovering the vulnerability and helping the patching effort. This comes at a time when Intel is said to be ending its lucrative bug bounty program.

There is a fix available. Any version of GCC from 26.08.28.01, GBT_VGA_26.08.24.01 or later has the mitigation in place. Looks like the current GCC version is 26.09.10.01. The mitigation includes the following:

  • Enhanced Access Control: Implemented strict security descriptors to ensure that the driver device objects are only accessible to authorized system accounts, preventing unprivileged users from interacting with the driver.
  • Interface Hardening: Removed unnecessary and high-risk interfaces that allowed direct physical memory mapping.
  • Privilege Validation: Integrated mandatory privilege checks for all hardware-access functions to ensure only requests with appropriate administrative rights are processed.
  • Input Validation: Implemented rigorous validation for all IOCTL input parameters to block access to restricted hardware registers and configuration spaces.

So, get that software updated. And if you're keen to stay on top of these things, here's the Gigabyte page with all its security disclosures.

Keep up to date with the most important stories and the best deals, as picked by the PC Gamer team.

MSI MPG 321URX gaming monitor

Jacob has been writing about PC hardware and technology for over eight years. He earned his first byline at PCGamesN before joining PC Gamer. He spends most of his time building PCs, running benchmarks, and trying his best to learn Linux.

Read Entire Article