CVE-2026-4416
CVE-2026-4416
8.5
HighPublished:
Last updated:
Source:twcert@cert.org.tw
Analyzed
Weakness (CWE)
CVSS Vector
v4.0- Attack Vector
- Local
- Attack Complexity
- Low
- Attack Requirements
- None
- Privileges Required
- Low
- User Interaction
- None
- Confidentiality (Vulnerable)
- High
- Integrity (Vulnerable)
- High
- Availability (Vulnerable)
- High
- Confidentiality (Subsequent)
- None
- Integrity (Subsequent)
- None
- Availability (Subsequent)
- None
Description
The Performance Library component of Gigabyte Control Center has an Insecure Deserialization vulnerability. Authenticated local attackers can send a malicious serialized payload to the EasyTune Engine service, resulting in privilege escalation.
References
twcert@cert.org.tw
https://www.twcert.org.tw/en/cp-139-10806-fbc4a-2.htmltwcert@cert.org.tw
https://www.twcert.org.tw/tw/cp-132-10805-a53f6-1.html