Vendor
Integer Overflow Vulnerability in MSI Dragon Center NTIOLib_X64.sys
1 TTP 1 CVEA local integer overflow vulnerability in the MmioWritePath function of the MSI Dragon Center driver allows local attackers to escalate privileges via manipulation of argument count or element size parameters.
Command Injection in MSI Radix AXE6600 Router
1 rule 3 TTPs 11 CVEsThe MSI Radix AXE6600 router firmware version v781521 is vulnerable to remote command injection via the wps.cgi interface, allowing unauthenticated attackers to execute arbitrary commands with root privileges.
CVE-2026-57851 — MSI Feature Manager Kernel Driver Local Privilege Escalation
1 TTP 1 CVEA local privilege escalation vulnerability (CVE-2026-57851) exists in the MSI Feature Manager's KernCoreLib64.sys kernel driver that allows any local user to perform arbitrary physical memory read/write and unrestricted I/O port operations by accessing exposed IOCTL handlers without requiring administrator privileges, enabling manipulation of kernel objects, tampering with kernel-mode callbacks, bypassing Protected Process Light, and disabling security software.