CVE-2026-4415
CVSS 8.1 HIGH: gigabyte Control Center developed by GIGABYTE has an Arbitrary File Write vulnerability. EPSS 0.9% (59º percentile).
Vulnerabilità ed exploit
GIGABYTE Control Center — l'utilità Windows preinstallata sui laptop e sulle schede madri Gigabyte — contiene una falla di scrittura arbitraria di file non autenticata. Il bug esiste quando la funzione “pairing” dello strumento è abilitata nelle versioni 25.07.21.01 e precedenti. Quando “pairing” è abilitato, attori remoti non autenticati possono scrivere file in qualsiasi posizione del sistema operativo sottostante. Taiwan CERT e GIGABYTE affermano che uno sfruttamento riuscito potrebbe portare a arbitrary code execution, privilege escalation o denial-of-service. Il problema è tracciato come CVE-2026-4415 con un punteggio CVSS v4.0 di 9.2.
1 fonte · 31 mar
CVSS 8.1 HIGH: gigabyte Control Center developed by GIGABYTE has an Arbitrary File Write vulnerability. EPSS 0.9% (59º percentile).
BleepingComputer
GIGABYTE Control Center vulnerable to arbitrary file write flaw
The GIGABYTE Control Center is vulnerable to an arbitrary file-write flaw that could allow a remote, unauthenticated attacker to access files on vulnerable hosts.
originalePart of the PlainSec briefing for 2026-04-01
Every edition of this story: Utility GIGABYTE preinstallata consente la scrittura arbitraria di file senza autenticazione