Vulnerabilities
9 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-4416 | The Performance Library component of Gigabyte Control Center has an Insecure Deserialization vulnerability. The Performance Library component of Gigabyte Control Center has an Insecure Deserialization vulnerability. Authenticated local attackers can send a malicious serialized payload to the EasyTune Engine service, resulting in privilege escalation. NVD description · AI analysis pending | 8.5 | <1% |
| — | ||
| CVE-2026-4415 | Gigabyte Control Center developed by GIGABYTE has an Arbitrary File Write vulnerability. Gigabyte Control Center developed by GIGABYTE has an Arbitrary File Write vulnerability. When the pairing feature is enabled, unauthenticated remote attackers can write arbitrary files to any location on the underlying operating system, leading to arbitrary code execution or privilege escalation. NVD description · AI analysis pending | 9.2 | <1% |
| — | ||
| CVE-2019-7630 | An issue was discovered in gdrv.sys in Gigabyte APP Center before 19.0227.1. An issue was discovered in gdrv.sys in Gigabyte APP Center before 19.0227.1. The vulnerable driver exposes a wrmsr instruction via IOCTL 0xC3502580 and does not properly filter the target Model Specific Register (MSR). Allowing arbitrary MSR writes can lead to Ring-0 code execution and escalation of privileges. NVD description · AI analysis pending | 7.2 | 3% | PoC |
| — | |
| CVE-2018-19323 | Privilege Escalation in GIGABYTE GDrv Driver (APP Center, AORUS, OC GURU II, XTREME) The GDrv low-level kernel driver bundled with GIGABYTE's APP Center (1.05.21 and earlier), AORUS GRAPHICS ENGINE (before 1.57), XTREME GAMING ENGINE (before 1.26), and OC GURU II (2.08) exposes functionality that allows reading and writing Machine Specific Registers (MSRs) without sufficient access control. An attacker who reaches this exposed driver functionality can send crafted requests to write arbitrary MSRs, gaining kernel (ring-0) privileges and thereby escalating from limited access to full control of the host. The flaw is rated critical (CVSS 9.8) with no privileges or user interaction required per the published vector. It affects Windows systems where the GIGABYTE utility software that installs the GDrv driver is present, typically enthusiast overclocking and monitoring tools bundled with GIGABYTE motherboards and graphics cards. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-10-24 with known ransomware use, and recent reporting indicates active exploitation alongside other driver vulnerabilities. Do: Apply vendor updates per CISA guidance: APP Center later than 1.05.21, AORUS GRAPHICS ENGINE 1.57 or later, XTREME GAMING ENGINE 1.26 or later, and OC GURU II later than 2.08, which ship a corrected GDrv driver. Audit Windows endpoints for the GDrv (gdrv.sys) low-level driver and uninstall unused GIGABYTE utility software to close the exposed interface. Because CISA lists this with known ransomware use, prioritize remediation on workstations and user endpoints rather than assuming only servers are affected. | 9.8 group max | 8% | KEV ransomware PoC ×2 |
| mass~millions of Windows systems (GIGABYTE utility bundles install the vulnerable GDrv driver) | |
| CVE-2017-3197 +1 in the same advisory: …3198 | GIGABYTE BRIX UEFI firmware for the GB-BSi7H-6500 (version F6) and GB-BXi7-5775 (version F2) platforms does not securely implement BIOSWE, BLE, SMM_BWP, and PRx GIGABYTE BRIX UEFI firmware for the GB-BSi7H-6500 (version F6) and GB-BXi7-5775 (version F2) platforms does not securely implement BIOSWE, BLE, SMM_BWP, and PRx features. As a result, the BIOS is not protected from arbitrary write access and may permit modifications to the SPI flash. NVD description · AI analysis pending | 9.8 | 6% | PoC ×3 |
| — |