Executive brief
A vulnerability exists in the lighting control software for GIGABYTE motherboards and components. An attacker who already has basic access to a computer can exploit this flaw to gain full control over the entire operating system. This could allow them to bypass security protections, access sensitive data, or disable the system entirely.
Technical details
An Improper Access Control vulnerability (CWE-782) exists in the MBStorage DRAM lighting control module within Gigabyte Control Center (GCC). The issue resides in the bundled driver 'MyPortIO_x64.sys', which fails to properly restrict Input/Output Control (IOCTL) commands. An authenticated local attacker can send crafted IOCTL commands to the driver to perform arbitrary reads and writes to physical memory. This capability allows the attacker to escalate privileges from a standard user to kernel-level (Ring 0) authority. The vulnerability is addressed in MBStorage version 26.06.03.01.
Affected products
- GIGABYTE Gigabyte Control Center (GCC) MBStorage Module 26.02.10.01 and earlier
Timeline
- 2026-07-13: advisory: Initial disclosure by TWCERT/CC and NVD publication.
- 2026-07-13: patched: Update to MBStorage version 26.06.03.01 or later released.