Junglewise Threat Intelligence

CVE-2026-57851: MSI Feature Manager privilege escalation in KernCoreLib64.sys

CVE-2026-57851 · Severity: high · CVSS 7.8 · Published 2026-07-07

Vendors: MSI.

Executive brief

A security vulnerability exists in a system driver used by MSI Feature Manager software. This flaw allows a standard user who is already logged into the computer to gain full administrative control over the system. An attacker could use this access to steal sensitive data, disable antivirus software, or permanently damage the operating system.

Technical details

A local privilege escalation vulnerability exists in the MSI KernCoreLib64.sys kernel driver due to insufficient access control on IOCTL handlers (CWE-782). The driver's device object is accessible to non-privileged users, allowing them to issue IOCTL requests that grant direct physical memory read/write access and unrestricted I/O port operations. An attacker can leverage these capabilities to manipulate kernel objects, tamper with kernel-mode callbacks, bypass Protected Process Light (PPL) protections, and disable security software. This vulnerability requires local access but no user interaction. Proof-of-concept code has been identified in public repositories.

Affected products

  • Micro-Star International (MSI) KernCoreLib64.sys All versions included in MSI Feature Manager

Timeline

  • 2026-07-07: disclosed
  • 2026-07-07: advisory

References