Gigabyte Control Center developed by GIGABYTE has an Arbitrary File Write vulnerability. When the pairing feature is enabled, unauthenticated remote attackers can write arbitrary files to any location on the underlying operating system, leading to arbitrary code execution or privilege escalation.
When the pairing feature is enabled in Gigabyte Control Center, the application does not verify the identity of the requester or the target file path. The vulnerability combines path traversal (CWE-23) and write outside intended buffer or location (CWE-787) characteristics, allowing an attacker to transmit any file over the network and place it in a selected operating system location. This results in the ability to inject malicious code in locations executed by the system or applications with elevated privileges.
An attacker can achieve remote code execution (RCE) on a vulnerable machine or escalate their privileges to system level, gaining full control over the host.
Patches available from the vendor should be applied according to references (https://www.twcert.org.tw/en/cp-139-10804-689cd-2.html). Until an update is applied, it is recommended to disable the pairing feature in Gigabyte Control Center and restrict network access to the application using a firewall.
Gigabyte Control Center — versions indicated in vendor references (TWCERT); vulnerability is active when the device pairing feature is enabled.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XGigabyte Control Center
APPGigabyte< 25.12.10.01
Related vulnerabilities
Gigabyte GDrv — niekontrolowany dostęp do rejestrów MSR przez sterownik niskopoziomowy
Gigabyte BRIX UEFI — brak weryfikacji podpisu aktualizacji firmware przez HTTP
Gigabyte BRIX UEFI — brak ochrony zapisu BIOS/SPI flash
The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE befo...
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTRE...