Gigabyte admits an oopsie with Gigabyte Control Center software leaving kernel exposed to attackers
Gigabyte has identified and released patches for critical vulnerabilities in its Control Center software affecting its motherboard ecosystem. The vulnerabilities impact kernel drivers GVCIDrv64.sys and gdrv3.sys, allowing local attackers to escalate privileges to kernel level (Ring 0). If exploited, these flaws could enable Local Privilege Escalation (LPE) and complete system compromise, potentially granting attackers NT AUTHORITY\SYSTEM access on Windows systems.
The affected software manages Gigabyte motherboard settings and hardware control features. While exploitation requires local access to a target system—limiting the practical risk of widespread attacks—the kernel-level access potential makes immediate patching critical. Gigabyte has already released a mitigated version and strongly recommends all users with Gigabyte motherboards running the Control Center software download and install the latest update from the company’s website.
This incident highlights the importance of maintaining current system software and drivers, particularly applications with direct kernel access. Despite the relatively low risk of remote exploitation due to the local-access requirement, security best practices dictate swift patching to close privilege escalation vectors.