News

Gigabyte Control Center: Security Flaw Grants Attackers Kernel Access

If you own a Gigabyte motherboard and use its Control Center software, it's time to pay attention: Gigabyte has confirmed a security vulnerability that could allow attackers to gain kernel-level access to your system. PC Gamer reports this, citing an official advisory from the manufacturer.

Specifically, the flaw is in the MBStorage module of Gigabyte Control Center software, which is actually only responsible for RAM lighting. The module includes a kernel driver called MyPortIO_x64.sys, and this is precisely what can be exploited. An attacker with local access to your computer can use it to read and write arbitrary physical memory — thereby escalating privileges to kernel level (Ring 0). Once this is achieved, they essentially have full control over the system, including the ability to bypass security software.

Am I Affected as a Gigabyte User?

The vulnerability is identified as CVE-2026-9492 and is rated 7.8 out of 10 according to the CVSS 3.1 standard — categorizing it as "High." All versions of the MBStorage module prior to 26.06.03.01 are affected. These modules are installed as part of the Gigabyte Control Center software on many current Gigabyte motherboards with RGB RAM support. Important: An attacker already needs local, authenticated access to your PC for this exploit; a remote attack over the internet is not possible according to current knowledge. Nevertheless, this is no reason to relax, as malware already present on your system could use this flaw as the final step to gain full control. Gigabyte lists the full details in its official Security Advisory.

  • CVE-2026-9492 (CWE-782: Exposed IOCTL with insufficient access control)
  • Affected: MBStorage module (RAM lighting control) of the Gigabyte Control Center software, specifically the kernel driver MyPortIO_x64.sys
  • Affected versions: all MBStorage versions prior to 26.06.03.01
  • CVSS 3.1 Score: 7.8 (High)
  • Prerequisite for attack: local, authenticated access to the system

How Do I Protect Myself from the Security Flaw?

The good news: Gigabyte has already fixed the bug; you just need to take action. Here's how:

  • Open the Gigabyte Control Center app on your PC
  • In the update section, look for a new MBStorage version (26.06.03.01 or newer) and install it
  • Alternatively: Download the complete, latest Gigabyte Control Center package directly from the official product page
  • Regularly check the Gigabyte Download Center anyway for new software or BIOS updates for your motherboard
  • Restart your PC after installation

This vulnerability is part of a series of security issues found in Gigabyte software this year. As recently as summer 2026, PC Gamer reported an even more critical vulnerability in the Control Center software, which allowed unauthenticated file writes to the system if the pairing function was enabled. A warning also surfaced in 2026 regarding Gigabyte motherboard BIOS versions for older Intel processors. Users who utilize RGB software, overclocking tools, and similar add-on programs from motherboard manufacturers potentially open themselves up to additional attack surfaces — this applies not just to Gigabyte, but to the entire industry. Our advice: always keep such kernel-adjacent software up-to-date and uninstall tools you don't actually need.

Source: PC Gamer, Gigabyte Security Advisory

It's best to check your Gigabyte Control Center version right now and install the update — let us know in the comments if you were affected!

Comments (0)

No comments yet — be the first to share your take.