The Performance Library component of Gigabyte Control Center has an Insecure Deserialization vulnerability. Authenticated local attackers can send a malicious serialized payload to the EasyTune Engine service, resulting in privilege escalation.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Please update to version 25.12.31.01 or later.
Workaround
No workaround given by the vendor.
References
History
Mon, 30 Mar 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Performance Library component of Gigabyte Control Center has an Insecure Deserialization vulnerability. Authenticated local attackers can send a malicious serialized payload to the EasyTune Engine service, resulting in privilege escalation. | |
| Title | GIGABYTE|Performance Library - Insecure Deserialization | |
| Weaknesses | CWE-502 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2026-03-30T07:52:21.641Z
Reserved: 2026-03-19T02:53:09.032Z
Link: CVE-2026-4416
No data.
Status : Received
Published: 2026-03-30T08:16:18.360
Modified: 2026-03-30T08:16:18.360
Link: CVE-2026-4416
No data.
OpenCVE Enrichment
No data.
Weaknesses