• News/
  • https://www.bleepingcomputer.com/news/security/gigabyte-control-center-vulnerable-to-arbitrary-file-write-flaw/

GIGABYTE Control Center vulnerable to arbitrary file write flaw

BleepingComputer
·
Bill Toulas
·
Published Mar 31, 2026
·
Updated

The GIGABYTE Control Center is vulnerable to an arbitrary file-write flaw that could allow a remote, unauthenticated attacker to access files on vulnerable hosts. The hardware maker says that successful exploitation could potentially lead to code execution on the underlying system, privilege escalation, and a denial-of-service condition. The GIGABYTE Control Center (GCC), which comes pre-installed on all the company’s laptops and motherboards, is GIGABYTE’s all-in-one Windows utility that lets users manage and configure their hardware. It supports hardware monitoring, fan control, performance tuning, RGB lighting control, driver and firmware updates, and device management. A feature in the Control Center is “pairing,” which allows the tool to communicate with other devices or services over the network. Systems with the 'pairing' option enabled on Control Center versions 25.07.21.01 and earlier are exposed to attacks. “When the pairing feature is enabled, unauthenticated remote attackers can write arbitrary files to any location on the underlying operating system, leading to arbitrary code execution or privilege escalation,” warned Taiwan’s CERT. The issue, tracked as CVE-2026-4415, was discovered by security researcher David Sprüngli. Based on the CVSS v4.0 scoring system, the issue has a critical severity rating (9.2 out of 10). Users are recommended to upgrade to the latest version of Control Center, currently 25.12.10.01, which includes fixes for download path management,...

Read full article

Affected Software

1 affected component
GIGABYTE Control Center<=25.07.21.01
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a security vulnerability in the GIGABYTE Control Center software.

2

What security implications are discussed in the article?

The article highlights an arbitrary file-write flaw that could allow remote, unauthenticated attackers to access files on vulnerable systems.

3

What products or software are affected by this vulnerability?

The vulnerability specifically affects the GIGABYTE Control Center software, particularly versions up to 25.07.21.01.

4

What could happen if this vulnerability is exploited?

Successful exploitation of this vulnerability could enable attackers to potentially access sensitive files on the affected hosts.

5

Has GIGABYTE acknowledged this vulnerability?

Yes, GIGABYTE has acknowledged the existence of this arbitrary file-write flaw in their Control Center software.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203
GIGABYTE Control Center vulnerable to arbitrary file write flaw - SecAlerts