---
id: CVE-2026-9492
title: >-
  The MBStorage DRAM lighting control module within Gigabyte Control Center
  (GCC) developed by GIGABYTE Technology has an Improper Access Control
  vulnerability
summary: >-
  The MBStorage DRAM lighting control module within Gigabyte Control Center
  (GCC) developed by GIGABYTE Technology has an Improper Access Control
  vulnerability. Authenticated local attackers can send specific IOCTL commands
  through the dri…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-782
published: '2026-07-13'
updated: '2026-07-13'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-9492'
references:
  - url: 'https://www.twcert.org.tw/en/cp-139-11034-f7f2f-2.html'
    label: twcert@cert.org.tw
  - url: 'https://www.twcert.org.tw/tw/cp-132-11033-97316-1.html'
    label: twcert@cert.org.tw
tags:
  - nvd
ingestedAt: '2026-07-13T04:24:09.736Z'
epss: 0.00157
epssPercentile: 0.05254
---

## Overview

The MBStorage DRAM lighting control module within Gigabyte Control Center (GCC) developed by GIGABYTE Technology has an Improper Access Control vulnerability. Authenticated local attackers can send specific IOCTL commands through the driver MyPortIO_x64.sys bundled with the module, thereby arbitrarily reading and writing physical memory and obtaining kernel-level privileges.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
