PT-2026-57623 · Gigabyte · Gigabyte Control Center
CVE-2026-9492
·
Published
2026-07-13
·
Updated
2026-07-15
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Gigabyte Control Center (affected versions not specified)
Description
The MBStorage DRAM lighting control module within Gigabyte Control Center (GCC) contains an improper access control issue. Authenticated local attackers can send specific IOCTL (Input/Output Control) commands through the
MyPortIO x64.sys driver bundled with the module. This allows the attacker to arbitrarily read and write physical memory, leading to the acquisition of kernel-level privileges.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
LPE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gigabyte Control Center