Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
gvcidrv64 — Proof-of-concept exploit for Gigabyte's GVCIDrv64.sys kernel driver, achieving local privilege escalation via arbitrary physical memory and I/O port read/write. | Kitploit
Tools/GitHubGitHub/mein-0/gvcidrv64
Privilege EscalationMemory ForensicsVulnerability AnalysisExploitationHardware SecurityRed TeamingBinary Exploitation
GitHubmein-0/gvcidrv64

gvcidrv64

Proof-of-concept exploit for Gigabyte's GVCIDrv64.sys kernel driver, achieving local privilege escalation via arbitrary physical memory and I/O port read/write.

View Repository
156 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

hi hackers.

GVCIDrv64.sys is the signed kernel driver that ships with Gigabyte's BIOS utility. It creates \\.\GVCIDrv64 with no security descriptor, so any local user can open it no admin, no UAC. It exposes 3 IOCTLs with zero access control: map 32 MB of physical memory (0x9C406580), unmap (0x9C406584), and raw I/O port read/write of 1/2/4 bytes (0x9C406588).

The trick is how 2 of them combine. The map IOCTL reads a PCI device's BAR0 and maps it but the port IOCTL lets you rewrite that BAR0 first. Point the BAR at any physical address, call map and 32 MB of your chosen RAM lands in your process. That is arbitrary physical read/write built out of 2 features that were each supposed to be harmless.

So what do we get? Arbitrary physical memory r/w and arbitrary i/o port access from an ordinary user account, with no memory corruption and no mitigations to fight. The exploit scans physical memory for the System process (pid 4), reads its token, overwrites its own process token and spawns a system shell. Data-only, no shellcode in kernel mode.

2 practical limits. BAR0 is 32-bit, so the window stays below 4 GB use a VM with ≤2 GB RAM. And the exploit briefly rewrites a NIC's BAR0, so disable the network adapter first or an interrupt during the swap will BSOD you.

Tested on Windows 10 x64 22H2 in VMware Workstation (2 GB RAM). The driver is already loaded on machines with Gigabyte's utility installed; the exploit can also load it via SCM on a test box.

gcc -O2 -o exploit.exe exploit.c -ladvapi32
exploit.exe

Reported to Gigabyte in June 2026. Gigabyte removed the driver entirely and replaced it with GvVbiosDrv64.sys in GBT_VGA_26.08.24.01 the old vulnerable driver is no longer present. Advisory: Security Advisory 2454.

arb_rw.c is a standalone physical memory read/write/dump tool.

SHA256  a2353030d4ea3ad9e874a0f7ff35bbfa10562c98c949d88cabab27102bbb8e48  GVCIDrv64.sys
Download Tool