News report

Gigabyte Patches Control Center Kernel Driver Flaws

Gigabyte says two Control Center kernel drivers could let authenticated local attackers reach Ring 0. GCC 26.08.28.01 or later contains the mitigation.

On this page
  1. Gigabyte says two Control Center drivers exposed dangerous hardware access
  2. The fix removes or restricts the risky driver interfaces
  3. Why motherboard utilities can become a security boundary
  4. Do not confuse this disclosure with Gigabyte’s separate DRAM-lighting driver flaw

Gigabyte says two Control Center drivers exposed dangerous hardware access

Gigabyte has disclosed multiple high-severity vulnerabilities in two kernel drivers installed with Gigabyte Control Center. The company says insufficient access controls and input validation in GVCIDrv64.sys and gdrv3.sys could allow an authenticated local attacker to map physical memory and directly access hardware through exposed driver interfaces.

The advisory rates the issue 8.8 out of 10 under CVSS 3.1. Gigabyte says successful exploitation could bypass operating-system memory protections and ultimately elevate a local attacker to kernel-level Ring 0 privileges, including NT AUTHORITY\SYSTEM. The CVE identifier is still listed as pending in Gigabyte’s September 21 advisory.

Gigabyte’s published scope and mitigation for the Control Center driver flaws
ItemGigabyte advisory
Affected softwareGigabyte Control Center 26.03.31.01 and earlier
Affected driversGVCIDrv64.sys and gdrv3.sys
SeverityCVSS 3.1: 8.8 (High)
Attack prerequisiteAuthenticated local access
MitigationGCC 26.08.28.01 / GBT_VGA 26.08.24.01 or later

The fix removes or restricts the risky driver interfaces

Gigabyte says the corrected software adds stricter security descriptors around the driver device objects, removes unnecessary interfaces capable of direct physical-memory mapping, requires appropriate privileges for hardware-access functions and validates IOCTL input against restricted hardware regions.

For users, the practical action is simpler than the underlying driver problem: update Gigabyte Control Center through GCC LiveUpdate or the support page for the relevant Gigabyte product. Gigabyte identifies Control Center 26.08.28.01 and GBT_VGA 26.08.24.01, or later releases, as mitigated versions.

Why motherboard utilities can become a security boundary

Hardware-control suites need capabilities ordinary desktop applications do not. Fan control, monitoring, RGB management and low-level device configuration can depend on privileged drivers that communicate directly with hardware. If a driver exposes overly broad operations to unprivileged software, that legitimate hardware access can become a path around Windows protections.

That is why the affected component matters even to users who never deliberately interact with a kernel driver. If Gigabyte Control Center is installed, the driver can form part of the system’s privileged attack surface. Keeping the utility updated therefore matters independently of whether its visible RGB or monitoring features appear to work correctly.

Do not confuse this disclosure with Gigabyte’s separate DRAM-lighting driver flaw

Gigabyte published a separate September advisory for CVE-2026-9492 in MyPortIO_x64.sys, a driver associated with the MBStorage DRAM-lighting component of Control Center. That issue also involved exposed low-level access, but it has a different affected component, CVE and mitigation version.

For the newly disclosed GVCIDrv64.sys and gdrv3.sys vulnerabilities, the relevant baseline is Gigabyte’s September 21 advisory and GCC 26.08.28.01 or later. Users should rely on the current support package for their exact motherboard or graphics product rather than trying to replace individual driver files manually.

Sources

Primary and technical sources

These sources support the reporting and analysis above. Current stories are updated when later evidence materially changes the facts.

  1. 01 GIGABYTE

    Arbitrary Physical Memory and I/O Port Access Vulnerability in GIGABYTE Control Center Kernel Driver
  2. 02 GIGABYTE

    Arbitrary Physical Memory Access Vulnerability in GIGABYTE Control Center - MyPortIO Driver
  3. 03 PC Gamer

    Gigabyte Control Center needs to be updated immediately admits Gigabyte

Related

Technical guide

How to Back Up Installed Drivers in Windows 11

Export third-party driver packages from the Windows 11 driver store with PnPUtil, preserve them before a reinstall, and understand what the backup does and does not contain.

Compatibility & upgrades

ATX vs Micro-ATX vs Mini-ITX Motherboard Sizes

Compare ATX, Micro-ATX, and Mini-ITX motherboard dimensions, mounting and case-fit implications without confusing board size with chipset features or performance.