logo

GIGABYTE Control Center vulnerable to arbitrary file write flaw

ID: 8af27e8c-8ed3-5148-b0c7-adf95b49368c

STIX ID: report--8af27e8c-8ed3-5148-b0c7-adf95b49368c

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2026-03-31

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

The GIGABYTE Control Center contains a critical arbitrary file-write vulnerability (CVE-2026-4415) in the 'pairing' feature affecting versions 25.07.21.01 and earlier; when pairing is enabled, unauthenticated remote attackers can write files to the underlying OS, potentially leading to code execution, privilege escalation, or denial-of-service. Taiwan CERT and the vendor advise immediate upgrade to GCC 25.12.10.01 and obtaining installers from the official portal.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.