CRITICAL🇵🇱 Wersja polska

CVE-2026-4415

CVSS 9.2v4.0pub. 2026-03-30upd. 2026-04-08

Gigabyte Control Center developed by GIGABYTE has an Arbitrary File Write vulnerability. When the pairing feature is enabled, unauthenticated remote attackers can write arbitrary files to any location on the underlying operating system, leading to arbitrary code execution or privilege escalation.

🤖 AI Analysis
How it works

When the pairing feature is enabled in Gigabyte Control Center, the application does not verify the identity of the requester or the target file path. The vulnerability combines path traversal (CWE-23) and write outside intended buffer or location (CWE-787) characteristics, allowing an attacker to transmit any file over the network and place it in a selected operating system location. This results in the ability to inject malicious code in locations executed by the system or applications with elevated privileges.

Impact

An attacker can achieve remote code execution (RCE) on a vulnerable machine or escalate their privileges to system level, gaining full control over the host.

Mitigation & patch

Patches available from the vendor should be applied according to references (https://www.twcert.org.tw/en/cp-139-10804-689cd-2.html). Until an update is applied, it is recommended to disable the pairing feature in Gigabyte Control Center and restrict network access to the application using a firewall.

Who is affected

Gigabyte Control Center — versions indicated in vendor references (TWCERT); vulnerability is active when the device pairing feature is enabled.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Gigabyte Control Center

    APP
    Gigabyte
    < 25.12.10.01
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCELPE
CWE
References

Related vulnerabilities

CVE-2018-19323CRITICAL9.8⚠ KEVPL ✓same vendor

Gigabyte GDrv — niekontrolowany dostęp do rejestrów MSR przez sterownik niskopoziomowy

CVE-2017-3198CRITICAL9.8PL ✓same vendor

Gigabyte BRIX UEFI — brak weryfikacji podpisu aktualizacji firmware przez HTTP

CVE-2017-3197CRITICAL9.8PL ✓same vendor

Gigabyte BRIX UEFI — brak ochrony zapisu BIOS/SPI flash

CVE-2018-19321HIGH7.8⚠ KEVsame vendor

The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE befo...

CVE-2018-19320HIGH7.8⚠ KEVsame vendor

The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTRE...