CVE-2026-4415
CVSS 8.1 HIGH: gigabyte Control Center developed by GIGABYTE has an Arbitrary File Write vulnerability. EPSS 1.0% (60th percentile).
Vulnerabilities & Exploits
GIGABYTE Control Center — the Windows utility preinstalled on Gigabyte laptops and motherboards — contains an unauthenticated arbitrary file-write flaw. The bug exists when the tool’s “pairing” feature is enabled on versions 25.07.21.01 and earlier. When pairing is enabled, unauthenticated remote actors can write files to any location on the underlying operating system. Taiwan CERT and GIGABYTE say successful exploitation could lead to arbitrary code execution, privilege escalation, or denial-of-service. The issue is tracked as CVE-2026-4415 with a CVSS v4.0 score of 9.2.
1 source · Mar 31
CVSS 8.1 HIGH: gigabyte Control Center developed by GIGABYTE has an Arbitrary File Write vulnerability. EPSS 1.0% (60th percentile).
BleepingComputer
GIGABYTE Control Center vulnerable to arbitrary file write flaw
The GIGABYTE Control Center is vulnerable to an arbitrary file-write flaw that could allow a remote, unauthenticated attacker to access files on vulnerable hosts.
originalPart of the PlainSec briefing for 2026-04-01
Every edition of this story: Preinstalled GIGABYTE Utility Allows Unauthenticated Arbitrary File Write