PC HARDWARE GIGABYTE Control Center Update Patches Critical 8.8 CVSS Kernel Flaws GAMES Floor796 browser game packs pixel art references to games and movies GAMES Sonic the Hedgehog Movie Saved Franchise from Cancellation, Says Sega Boss GAMES Xbox Moves Halo Development to Activision Amid 268 Job Cuts GAMES Pokemon Card Collector Convicted of GPS Stalking to Track Restocks GAMES Activision to Lead Next Halo Game Development GAMES Rainbow Six Siege Season Four Launches During GTA 6 Release CONSOLES Microsoft Xbox Restructuring Nears End as Division Hits 75% Milestone INTEL Microsoft Surface Minos Rumored With 12-Inch Display and Nvidia RTX Spark NINTENDO AI Coded GoldenEye 007 SNES Port Runs on Super FX2 Chip STEAM Dancing with Ghosts Early Access Launches on Steam for $14.99 GAMES Microsoft Shuffles Xbox Game Studios: Halo, Rare Move to Activision INTEL Durabook Z14I-DX3: Rugged Laptop with Three 14-Inch Screens GAMES Blizzard Bans WoW Classic Gold Buyers Permanently Starting Nov 4

GIGABYTE Control Center Update Patches Critical 8.8 CVSS Kernel Flaws

Owen Carter 0 comments 2 min read

GIGABYTE released a security update for Control Center to fix critical kernel driver flaws allowing local attackers to map physical memory.

GIGABYTE motherboard with Control Center software interface
PC HARDWARE

GIGABYTE has issued a security advisory for its Control Center software due to critical flaws in the underlying kernel drivers. This update matters because the vulnerabilities allow authenticated local attackers to bypass access controls and map physical memory. Users who manage their motherboard settings through this utility need to apply the patch to prevent unauthorized hardware access.

GIGABYTE motherboard with Control Center software interface
GIGABYTE Control Center requires an immediate update to address kernel driver vulnerabilities.

GIGABYTE urges motherboard owners to install the patched driver version immediately

The affected software is the GIGABYTE Control Center, which serves as the primary interface for configuring GIGABYTE motherboard features. The security flaws reside specifically in the GVCIDrv64.sys and gdrv3.sys kernel drivers. These components handle input/output control requests that the operating system passes to the hardware.

GIGABYTE identified the root cause as insufficient access control and improper validation of input parameters within the driver IOCTL interfaces. The company disclosed that authenticated local attackers can exploit these gaps to perform unauthorized operations. This includes arbitrary physical memory mapping and direct hardware access, which could compromise system stability or security.

The vulnerability carries a CVSS rating of 8.8, reflecting a high severity level that demands immediate attention. GIGABYTE confirmed that the issue requires local access and cannot be exploited remotely. This constraint limits the attack surface to users who already have valid login credentials on the affected machine.

The fixed version is GIGABYTE Control Center v26.08.28.01. GIGABYTE states, 'The vulnerabilities exist in the kernel drivers' IOCTL interfaces. Due to insufficient access control and improper validation of input parameters, authenticated local attackers can perform unauthorized operations, including arbitrary physical memory mapping and direct hardware access.' Users should download this specific version to resolve the security risks.

This advisory addresses the specific kernel driver flaws reported by security researchers. GIGABYTE has prioritized the fix for the Control Center software to protect motherboard users from local privilege escalation. Applying the update ensures the drivers enforce proper input validation and access controls.

Source: TweakTown

Discussion

0 comments

Leave a comment