GIGABYTE has issued a security advisory for its Control Center software due to critical flaws in the underlying kernel drivers. This update matters because the vulnerabilities allow authenticated local attackers to bypass access controls and map physical memory. Users who manage their motherboard settings through this utility need to apply the patch to prevent unauthorized hardware access.

GIGABYTE urges motherboard owners to install the patched driver version immediately
The affected software is the GIGABYTE Control Center, which serves as the primary interface for configuring GIGABYTE motherboard features. The security flaws reside specifically in the GVCIDrv64.sys and gdrv3.sys kernel drivers. These components handle input/output control requests that the operating system passes to the hardware.
GIGABYTE identified the root cause as insufficient access control and improper validation of input parameters within the driver IOCTL interfaces. The company disclosed that authenticated local attackers can exploit these gaps to perform unauthorized operations. This includes arbitrary physical memory mapping and direct hardware access, which could compromise system stability or security.
The vulnerability carries a CVSS rating of 8.8, reflecting a high severity level that demands immediate attention. GIGABYTE confirmed that the issue requires local access and cannot be exploited remotely. This constraint limits the attack surface to users who already have valid login credentials on the affected machine.
The fixed version is GIGABYTE Control Center v26.08.28.01. GIGABYTE states, 'The vulnerabilities exist in the kernel drivers' IOCTL interfaces. Due to insufficient access control and improper validation of input parameters, authenticated local attackers can perform unauthorized operations, including arbitrary physical memory mapping and direct hardware access.' Users should download this specific version to resolve the security risks.
This advisory addresses the specific kernel driver flaws reported by security researchers. GIGABYTE has prioritized the fix for the Control Center software to protect motherboard users from local privilege escalation. Applying the update ensures the drivers enforce proper input validation and access controls.
Source: TweakTown

Discussion
0 comments