PT-2026-28806 · Gigabyte · Gigabyte Control Center
David Spruengli
·
Published
2026-03-30
·
Updated
2026-04-01
·
CVE-2026-4415
CVSS v3.1
8.1
High
| AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Gigabyte Control Center (affected versions not specified)
Description
Gigabyte Control Center developed by GIGABYTE contains a flaw that allows unauthenticated remote attackers to write arbitrary files to any location on the underlying operating system when the pairing feature is enabled. This can lead to arbitrary code execution or privilege escalation. It is estimated that millions of gaming rigs may be affected. The vulnerability allows attackers to write files anywhere on the system.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Relative Path Traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gigabyte Control Center