
Proof-of-concept exploit for Gigabyte's GVCIDrv64.sys kernel driver, achieving local privilege escalation via arbitrary physical memory and I/O port read/write.
hi hackers.
GVCIDrv64.sys is the signed kernel driver that ships with Gigabyte's BIOS utility. It creates \\.\GVCIDrv64 with no security descriptor, so any local user can open it no admin, no UAC. It exposes 3 IOCTLs with zero access control: map 32 MB of physical memory (0x9C406580), unmap (0x9C406584), and raw I/O port read/write of 1/2/4 bytes (0x9C406588).
The trick is how 2 of them combine. The map IOCTL reads a PCI device's BAR0 and maps it but the port IOCTL lets you rewrite that BAR0 first. Point the BAR at any physical address, call map and 32 MB of your chosen RAM lands in your process. That is arbitrary physical read/write built out of 2 features that were each supposed to be harmless.
So what do we get? Arbitrary physical memory r/w and arbitrary i/o port access from an ordinary user account, with no memory corruption and no mitigations to fight. The exploit scans physical memory for the System process (pid 4), reads its token, overwrites its own process token and spawns a system shell. Data-only, no shellcode in kernel mode.
2 practical limits. BAR0 is 32-bit, so the window stays below 4 GB use a VM with ≤2 GB RAM. And the exploit briefly rewrites a NIC's BAR0, so disable the network adapter first or an interrupt during the swap will BSOD you.
Tested on Windows 10 x64 22H2 in VMware Workstation (2 GB RAM). The driver is already loaded on machines with Gigabyte's utility installed; the exploit can also load it via SCM on a test box.
gcc -O2 -o exploit.exe exploit.c -ladvapi32
exploit.exe
Reported to Gigabyte in June 2026. Gigabyte removed the driver entirely and replaced it with GvVbiosDrv64.sys in GBT_VGA_26.08.24.01 the old vulnerable driver is no longer present. Advisory: Security Advisory 2454.
arb_rw.c is a standalone physical memory read/write/dump tool.
SHA256 a2353030d4ea3ad9e874a0f7ff35bbfa10562c98c949d88cabab27102bbb8e48 GVCIDrv64.sys