Those with a GIGABYTE motherboard in their PC should be aware of a fresh vulnerability in the company's Control Center software that requires action now.

PC Gamer noticed the security advisory which was posted warning about vulnerabilities in the drivers relating to the GIGABYTE Control Center app.
There are "multiple security vulnerabilities" in GVCIDrv64.sys and gdrv3.sys, we're told, and you should update to the latest version of the Control Center which has them patched.
GIGABYTE notes: "The vulnerabilities exist in the kernel drivers' IOCTL interfaces. Due to insufficient access control and improper validation of input parameters, authenticated local attackers can perform unauthorized operations, including arbitrary physical memory mapping and direct hardware access."
The end result could be a "complete system compromise" GIGABYTE advises, but there is some good news here which you likely spotted - the local aspect.
This isn't a vulnerability that can be exploited remotely; rather, it requires the attacker to be local, limiting the potential damage here.
Still, it's not a flaw that you want to have on your PC, so you should update the GIGABYTE Control Center software as soon as you can.

The version you need with the relevant security fixes is the GIGABYTE Control Center v26.08.28.01.
GIGABYTE credits two individuals for helping discover and stamp out this flaw, and apparently Mohamed Alzhrani (0xMaz) and Subhan Sultanov (me1n) have been "invaluable in developing a swift and effective response".

Frequently Asked Questions
Open a question for an answer from TweakTown's coverage of this news, or ask your own below.
How do I check whether my GIGABYTE Control Center install is on version v26.08.28.01 or older?
Do GVCIDrv64.sys and gdrv3.sys get updated automatically with Control Center, or do they need a separate fix?
Can this vulnerability be exploited remotely, or does an attacker need local access first?
What kinds of malicious actions were possible through the Control Center kernel driver flaws?
Have a question that isn't listed here? Ask below, and TweakBot will answer it.
This security issue has a CVSS (Common Vulnerability Scoring System) rating of 8.8 (out of 10), meaning it's a high risk in terms of the level of access that could be leveraged via an exploit.







