PT-2026-57623 · Gigabyte · Gigabyte Control Center

CVE-2026-9492

·

Published

2026-07-13

·

Updated

2026-07-15

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Gigabyte Control Center (affected versions not specified)
Description The MBStorage DRAM lighting control module within Gigabyte Control Center (GCC) contains an improper access control issue. Authenticated local attackers can send specific IOCTL (Input/Output Control) commands through the MyPortIO x64.sys driver bundled with the module. This allows the attacker to arbitrarily read and write physical memory, leading to the acquisition of kernel-level privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-9492

Affected Products

Gigabyte Control Center