Gigabyte Patched Critical Software Vulnerabilities

The update resolves flaws in kernel drivers that could allow unauthorized system access.

Updated on Sept. 22, 2026 in Cybersecurity

Gigabyte Patched Critical Software Vulnerabilities

Live Poll

Do you regularly update your computer software to protect against potential security vulnerabilities?

Gigabyte has released version 26.08.28.01 of its Control Center software to address multiple security vulnerabilities. These flaws could potentially be exploited by an authenticated local attacker to gain complete system compromise.

Why it matters

Fixing these vulnerabilities is essential as the flaws could permit unauthorized hardware access and physical memory mapping. This update mitigates the risk of complete system compromise on affected machines.

The vulnerabilities were assigned a high severity CVSS rating of 8.8 out of 10. This score reflects the risk posed by the flaws which allow for arbitrary physical memory mapping and direct hardware access.

The players

Gigabyte

A major manufacturer of computer hardware components, motherboards, and integrated software utilities.

Mohamed Alzhrani

A security researcher credited with the discovery of the kernel driver vulnerabilities.

Subhan Sultanov

A security researcher credited with the discovery of the kernel driver vulnerabilities.

The details

The security issues reside within the kernel drivers GVCIDrv64.sys and gdrv3.sys, which are components that operate with high-level privileges in the operating system. Attackers exploit IOCTL (Input/Output Control) interfaces, which are channels for communication between user applications and kernel drivers, due to poor access control and incorrect input validation. These flaws allow an authenticated local attacker to bypass standard system protections to execute unauthorized operations.

Timeline

  1. September 22, 2026: The security patch was officially disclosed.

The Tech Race

The CVSS rating of 8.8 serves as the industry standard benchmark for evaluating the severity of software vulnerabilities like those found in the Gigabyte Control Center. This disclosure follows the standard industry practice of scoring vulnerabilities using the CVSS framework to inform users of potential risk.

Users of Gigabyte hardware should update their Control Center software to version 26.08.28.01 immediately to patch these drivers. This update is necessary for any user running the utility on their local machine to maintain system security.

The takeaway

The discovery by Mohamed Alzhrani and Subhan Sultanov highlights the persistent risk of high-privilege kernel drivers in manufacturer software. Users should monitor Gigabyte support channels for future security bulletins regarding their installed utility software.

Further reading

For more information on current trends in software security, visit our Cybersecurity section.

Live Poll

Do you regularly update your computer software to protect against potential security vulnerabilities?