Impact
The MBStorage DRAM lighting control module in Gigabyte Control Center contains an improper driver access control flaw. An authenticated local user can send specially crafted IOCTL commands to the bundled MyPortIO_x64.sys driver, allowing arbitrary reading and writing of physical memory and thus kernel‑level privilege escalation. This weakness is classified as CWE‑782: improper driver access control.
Affected Systems
The affected vendor is Gigabyte. The product impacted is MBStorage bundled within Gigabyte Control Center. Versions prior to 26.06.03.01 contain the vulnerable MyPortIO_x64.sys driver; the fix is delivered in MBStorage 26.06.03.01 or later.
Risk and Exploitability
The CVSS score of 8.5 classifies this as a high‑severity vulnerability. The EPSS score of <1% indicates a low probability of exploitation at this time. It is not listed in the CISA KEV catalog, so no confirmed attacks are known. Exploitation requires local authentication and interaction with the driver, meaning any user with local access on the machine can attempt the attack. The combination of local availability and kernel‑level privilege escalation represents a substantial risk to systems where administrative privileges are delegated to untrusted users.
OpenCVE Enrichment