"These vulnerabilities allow a local malicious actor to elevate privileges to the kernel level (Ring 0), potentially leading to Local Privilege Escalation (LPE) and complete system compromise (achieving NT AUTHORITY\SYSTEM)."
If you have a Gigabyte motherboard and use the Gigabyte Control Center (GCC) software, you'd better download the latest version of the software. While the risk of a local attacker hacking into your PC is pretty slim, it's best practice to just cover your butt before anything bad happens.
Gigabyte has listed a new vulnerability on its website that affects a pair of kernel drivers, GVCIDrv64.sys and gdrv3.sys. It says the drivers are components of the GCC software, which is widely recommended alongside the company's motherboards.
"The vulnerabilities exist in the kernel drivers' IOCTL interfaces." Gigabyte says of the cause of the vulnerability. "Due to insufficient access control and improper validation of input parameters, authenticated local attackers can perform unauthorized operations, including arbitrary physical memory mapping and direct hardware access.
An attacker can wield those vulnerable drivers through a "specially crafted" IOCTL request. In doing so, bypassing important memory protections and allowing them to elevate themselves to the most trusted level of your PC, the kernel.
Gigabyte thanks Mohamed Alzhrani (0xMaz) and Subhan Sultanov (me1n) for discovering the vulnerability and helping the patching effort. This comes at a time when Intel is said to be ending its lucrative bug bounty program.
There is a fix available. Any version of GCC from 26.08.28.01, GBT_VGA_26.08.24.01 or later has the mitigation in place. Looks like the current GCC version is 26.09.10.01. The mitigation includes the following:
- Enhanced Access Control: Implemented strict security descriptors to ensure that the driver device objects are only accessible to authorized system accounts, preventing unprivileged users from interacting with the driver.
- Interface Hardening: Removed unnecessary and high-risk interfaces that allowed direct physical memory mapping.
- Privilege Validation: Integrated mandatory privilege checks for all hardware-access functions to ensure only requests with appropriate administrative rights are processed.
- Input Validation: Implemented rigorous validation for all IOCTL input parameters to block access to restricted hardware registers and configuration spaces.
So, get that software updated. And if you're keen to stay on top of these things, here's the Gigabyte page with all its security disclosures.








English (US) ·