gigabyte kernel driver lpe
A local privilege escalation vulnerability exists in the Gigabyte BIOS utility kernel driver GVCIDrv64.sys. The driver exposes device interfaces with no access control, allowing any local user to perform arbitrary physical memory read/write and I/O port access. This enables an attacker to escalate privileges by manipulating process tokens and spawning a system shell. Gigabyte has removed the vulnerable driver and replaced it with a new driver in a later utility version.
AI Analysis
Technical Summary
The Gigabyte BIOS utility includes a signed kernel driver, GVCIDrv64.sys, which creates a device interface without security descriptors, allowing any local user to open it without administrative privileges or UAC prompts. The driver exposes three IOCTLs with no access control: mapping 32 MB of physical memory, unmapping it, and raw I/O port read/write. By rewriting a PCI device's BAR0 register to point to arbitrary physical memory and then mapping it, an attacker gains arbitrary physical memory read/write capabilities. This is combined with raw I/O port access to manipulate system memory safely. The exploit reads the System process token and overwrites the attacker's process token to escalate privileges to SYSTEM. The vulnerability was reported to Gigabyte in June 2026, who removed the vulnerable driver and replaced it with GvVbiosDrv64.sys in version GBT_VGA_26.08.24.01 of their BIOS utility.
Potential Impact
An unprivileged local user can gain arbitrary physical memory read/write and I/O port access, enabling privilege escalation to SYSTEM on affected Windows 10 x64 systems. This allows full system compromise without kernel memory corruption or mitigations. The exploit requires disabling the network adapter to avoid system crashes during BAR0 manipulation and is limited to systems with ≤4 GB physical memory due to 32-bit BAR0 addressing.
Mitigation Recommendations
Gigabyte has removed the vulnerable GVCIDrv64.sys driver and replaced it with GvVbiosDrv64.sys in BIOS utility version GBT_VGA_26.08.24.01. Users should update to this version or later to eliminate the vulnerable driver. No other mitigation is required as the vulnerable driver is no longer present in updated utilities.
gigabyte kernel driver lpe
Description
A local privilege escalation vulnerability exists in the Gigabyte BIOS utility kernel driver GVCIDrv64.sys. The driver exposes device interfaces with no access control, allowing any local user to perform arbitrary physical memory read/write and I/O port access. This enables an attacker to escalate privileges by manipulating process tokens and spawning a system shell. Gigabyte has removed the vulnerable driver and replaced it with a new driver in a later utility version.
Reddit Discussion
hi support pls https://github.com/mein-0/gvcidrv64/
Links cited in this discussion
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Gigabyte BIOS utility includes a signed kernel driver, GVCIDrv64.sys, which creates a device interface without security descriptors, allowing any local user to open it without administrative privileges or UAC prompts. The driver exposes three IOCTLs with no access control: mapping 32 MB of physical memory, unmapping it, and raw I/O port read/write. By rewriting a PCI device's BAR0 register to point to arbitrary physical memory and then mapping it, an attacker gains arbitrary physical memory read/write capabilities. This is combined with raw I/O port access to manipulate system memory safely. The exploit reads the System process token and overwrites the attacker's process token to escalate privileges to SYSTEM. The vulnerability was reported to Gigabyte in June 2026, who removed the vulnerable driver and replaced it with GvVbiosDrv64.sys in version GBT_VGA_26.08.24.01 of their BIOS utility.
Potential Impact
An unprivileged local user can gain arbitrary physical memory read/write and I/O port access, enabling privilege escalation to SYSTEM on affected Windows 10 x64 systems. This allows full system compromise without kernel memory corruption or mitigations. The exploit requires disabling the network adapter to avoid system crashes during BAR0 manipulation and is limited to systems with ≤4 GB physical memory due to 32-bit BAR0 addressing.
Mitigation Recommendations
Gigabyte has removed the vulnerable GVCIDrv64.sys driver and replaced it with GvVbiosDrv64.sys in BIOS utility version GBT_VGA_26.08.24.01. Users should update to this version or later to eliminate the vulnerable driver. No other mitigation is required as the vulnerable driver is no longer present in updated utilities.
Technical Details
- Source Type
- Subreddit
- ExploitDev+pwned+hacking
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Newsworthiness Assessment
- {"score":27,"reasons":["external_link","established_author","very_recent"],"isNewsworthy":true}
- Has External Source
- true
- Trusted Domain
- false
Threat ID: 6abd444b2a4e24523d49f039
Added to database: 09/30/2026, 17:18:03 UTC
Last enriched: 09/30/2026, 17:18:10 UTC
Last updated: 09/30/2026, 18:17:50 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.