Executive brief
A security vulnerability in MSI Center, a system management utility for MSI hardware, could allow a user with limited access to gain full administrative control over a computer. By exploiting a flaw in a specific system driver, an attacker can bypass security checks to run commands with the highest possible system permissions. This could lead to a complete compromise of the machine, including the ability to access any data or disable security software.
Technical details
An origin validation error (CWE-346) exists within the NTIOLib_X64.sys driver bundled with MSI Center. The driver fails to sufficiently validate the source or origin of commands sent to it, allowing a local process with low privileges to issue requests that the driver executes with kernel-level authority. An attacker who has already gained local code execution can exploit this flaw to escalate their privileges to SYSTEM. The vulnerability was addressed in MSI Center version 2.0.69.0.
Affected products
- MSI MSI Center 2.0.66.0 and versions prior to 2.0.69.0
Timeline
- 2026-03-09: other: Vulnerability reported to vendor
- 2026-07-15: patched: Fixed in MSI Center version 2.0.69.0
- 2026-07-15: disclosed: Coordinated public release of advisory
- 2026-07-29: advisory: NVD publication date