GIGABYTE Control Center — the Windows utility preinstalled on Gigabyte laptops and motherboards — contains an unauthenticated arbitrary file-write flaw. The bug exists when the tool’s “pairing” feature is enabled on versions 25.07.21.01 and earlier. When pairing is enabled, unauthenticated remote actors can write files to any location on the underlying operating system. Taiwan CERT and GIGABYTE say successful exploitation could lead to arbitrary code execution, privilege escalation, or denial-of-service. The issue is tracked as CVE-2026-4415 with a CVSS v4.0 score of 9.2.