Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Please update to version 25.12.31.01 or later.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 08 Apr 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:gigabyte:performance_library:*:*:*:*:*:*:*:* |
Wed, 01 Apr 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gigabyte
Gigabyte performance Library |
|
| Vendors & Products |
Gigabyte
Gigabyte performance Library |
Mon, 30 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 30 Mar 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Performance Library component of Gigabyte Control Center has an Insecure Deserialization vulnerability. Authenticated local attackers can send a malicious serialized payload to the EasyTune Engine service, resulting in privilege escalation. | |
| Title | GIGABYTE|Performance Library - Insecure Deserialization | |
| Weaknesses | CWE-502 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2026-03-30T15:08:37.998Z
Reserved: 2026-03-19T02:53:09.032Z
Link: CVE-2026-4416
Updated: 2026-03-30T15:08:28.901Z
Status : Analyzed
Published: 2026-03-30T08:16:18.360
Modified: 2026-04-08T19:23:47.020
Link: CVE-2026-4416
No data.
OpenCVE Enrichment
Updated: 2026-04-09T08:29:28Z