VYPR

Vendor CVEs

MSI

All CVEs

40 total · sorted by risk
  • CVE-2021-27965CriMar 5, 2021
    risk 0.65cvss 9.8epss 0.12

    The MsIo64.sys driver before 1.1.19.1016 in MSI Dragon Center before 2.0.98.0 has a buffer overflow that allows privilege escalation via a crafted 0x80102040, 0x80102044, 0x80102050, or 0x80102054 IOCTL request.

  • CVE-2026-71993CriAug 9, 2026
    risk 0.64cvss 9.8epss 0.01

    MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the openvpn function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the macfilter function to inject malicious commands and…

  • CVE-2026-71992CriAug 9, 2026
    risk 0.64cvss 9.8epss 0.01

    MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the macfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the macfilter function to inject malicious commands and…

  • CVE-2026-71991CriAug 9, 2026
    risk 0.64cvss 9.8epss 0.01

    MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for Telnet configuration that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability…

  • CVE-2026-71990CriAug 9, 2026
    risk 0.64cvss 9.8epss 0.01

    MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for SSH configuration that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through…

  • CVE-2026-71989CriAug 9, 2026
    risk 0.64cvss 9.8epss 0.01

    MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the porTrigger function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute…

  • CVE-2026-71988CriAug 9, 2026
    risk 0.64cvss 9.8epss 0.01

    MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the portFw function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute…

  • CVE-2026-71987CriAug 9, 2026
    risk 0.64cvss 9.8epss 0.01

    MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the alg function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute…

  • CVE-2026-71986CriAug 9, 2026
    risk 0.64cvss 9.8epss 0.01

    MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the dmz function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the dmz function to execute…

  • CVE-2026-71985CriAug 9, 2026
    risk 0.64cvss 9.8epss 0.01

    MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the accesscontrol function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the accesscontrol…

  • CVE-2026-71984CriAug 9, 2026
    risk 0.64cvss 9.8epss 0.01

    MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the urlfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the urlfilter function to inject malicious commands and…

  • CVE-2026-71983CriAug 8, 2026
    risk 0.64cvss 9.8epss 0.02

    MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the wps.cgi interface that allows remote attackers to execute arbitrary commands by injecting malicious input through the pin2g, pin5g, or pin6g parameters. Attackers can exploit…

  • CVE-2022-31877HigNov 28, 2022
    risk 0.57cvss 8.8epss 0.00

    An issue in the component MSI.TerminalServer.exe of MSI Center v1.0.41.0 allows attackers to escalate privileges via a crafted TCP packet.

  • CVE-2020-17382HigOct 2, 2020
    risk 0.54cvss 7.8epss 0.02

    The MSI AmbientLink MsIo64 driver 1.0.0.8 has a Buffer Overflow (0x80102040, 0x80102044, 0x80102050,and 0x80102054).

  • CVE-2025-27813HigApr 10, 2025
    risk 0.53cvss 8.1epss 0.00

    MSI Center before 2.0.52.0 has Missing PE Signature Validation.

  • CVE-2025-27812HigApr 10, 2025
    risk 0.53cvss 8.1epss 0.00

    MSI Center before 2.0.52.0 allows TOCTOU Local Privilege Escalation.

  • CVE-2019-16098HigSep 11, 2019
    risk 0.52cvss 7.8epss 0.18

    The driver in Micro-Star MSI Afterburner 4.6.2.15658 (aka RTCore64.sys and RTCore32.sys) allows any authenticated user to read and write to arbitrary memory, I/O ports, and MSRs. This can be exploited for privilege escalation, code execution under high privileges, and…

  • CVE-2024-3745HigMay 18, 2024
    risk 0.51cvss 7.8epss 0.00

    MSI Afterburner v4.6.6.16381 Beta 3 is vulnerable to an ACL Bypass vulnerability in the RTCore64.sys driver, which leads to triggering vulnerabilities like CVE-2024-1443 and CVE-2024-1460 from a low privileged user.

  • CVE-2021-32415HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.00

    EXEMSI MSI Wrapper Versions prior to 10.0.50 and at least since version 6.0.91 will introduce a local privilege escalation vulnerability in installers it creates.

  • CVE-2022-38532HigSep 19, 2022
    risk 0.51cvss 7.8epss 0.00

    Micro-Star International Co., Ltd MSI Center 1.0.50.0 was discovered to contain a vulnerability in the component C_Features of MSI.CentralServer.exe. This vulnerability allows attackers to escalate privileges via running a crafted executable.

  • CVE-2021-44903HigFeb 4, 2022
    risk 0.51cvss 7.8epss 0.00

    Micro-Star International (MSI) Center Pro <= 2.0.16.0 is vulnerable to multiple Privilege Escalation (LPE/EoP) vulnerabilities in the atidgllk.sys, atillk64.sys, MODAPI.sys, NTIOLib.sys, NTIOLib_X64.sys, WinRing0.sys, WinRing0x64.sys drivers components. All the vulnerabilities…

  • CVE-2021-44901HigFeb 4, 2022
    risk 0.51cvss 7.8epss 0.00

    Micro-Star International (MSI) Dragon Center <= 2.0.116.0 is vulnerable to multiple Privilege Escalation (LPE/EoP) vulnerabilities in the atidgllk.sys, atillk64.sys, MODAPI.sys, NTIOLib.sys, NTIOLib_X64.sys, WinRing0.sys, WinRing0x64.sys drivers components. All the…

  • CVE-2021-44900HigFeb 4, 2022
    risk 0.51cvss 7.8epss 0.00

    Micro-Star International (MSI) App Player <= 4.280.1.6309 is vulnerable to multiple Privilege Escalation (LPE/EoP) vulnerabilities in the NTIOLib_X64.sys and BstkDrv_msi2.sys drivers components. All the vulnerabilities are triggered by sending specific IOCTL requests.

  • CVE-2021-44899HigFeb 4, 2022
    risk 0.51cvss 7.8epss 0.00

    Micro-Star International (MSI) Center <= 1.0.31.0 is vulnerable to multiple Privilege Escalation vulnerabilities in the atidgllk.sys, atillk64.sys, MODAPI.sys, NTIOLib.sys, NTIOLib_X64.sys, WinRing0.sys, WinRing0x64.sys drivers components. All the vulnerabilities are triggered…

  • CVE-2021-29337HigJun 21, 2021
    risk 0.51cvss 7.8epss 0.01

    MODAPI.sys in MSI Dragon Center 2.0.104.0 allows low-privileged users to access kernel memory and potentially escalate privileges via a crafted IOCTL 0x9c406104 call. This IOCTL provides the MmMapIoSpace feature for mapping physical memory.

  • CVE-2020-13149HigMay 18, 2020
    risk 0.51cvss 7.8epss 0.00

    Weak permissions on the "%PROGRAMDATA%\MSI\Dragon Center" folder in Dragon Center before 2.6.2003.2401, shipped with Micro-Star MSI Gaming laptops, allows local authenticated users to overwrite system files and gain escalated privileges. One attack method is to change the…

  • CVE-2026-53876HigJun 17, 2026
    risk 0.47cvss 7.2epss 0.02

    RadiX AX6600 WiFi 6 Tri-Band Gaming Router contains an OS command injection vulnerability, which may lead to arbitrary command execution with the root privilege by a user who logs in to the web console as an administrator.

  • CVE-2022-34109HigSep 12, 2022
    risk 0.46cvss 7.1epss 0.00

    An issue in Micro-Star International MSI Feature Navigator v1.0.1808.0901 allows attackers to write arbitrary files to the directory \PromoPhoto\, regardless of file type or size.

  • CVE-2022-34108HigSep 12, 2022
    risk 0.46cvss 7.1epss 0.00

    An issue in the Feature Navigator of Micro-Star International MSI Feature Nagivator v1.0.1808.0901 allows attackers to cause a Denial of Service (DoS) via a crafted image or video file.

  • CVE-2025-14303MedDec 17, 2025
    risk 0.44cvss 6.8epss 0.00

    Certain motherboard models developed by MSI has a Protection Mechanism Failure vulnerability. Because IOMMU was not properly enabled, unauthenticated physical attackers can use a DMA-capable PCIe device to read and write arbitrary physical memory before the OS kernel and its…

  • CVE-2024-37726MedJul 3, 2024
    risk 0.44cvss 6.8epss 0.01

    Insecure Permissions vulnerability in Micro-Star International Co., Ltd MSI Center v.2.0.36.0 allows a local attacker to escalate privileges via the Export System Info function in MSI.CentralServer.exe

  • CVE-2024-12227MedDec 5, 2024
    risk 0.36cvss 5.5epss 0.00

    A vulnerability, which was classified as problematic, was found in MSI Dragon Center up to 2.0.146.0. This affects the function MmUnMapIoSpace in the library NTIOLib_X64.sys of the component IOCTL Handler. The manipulation leads to null pointer dereference. It is possible to…

  • CVE-2024-1460MedMar 7, 2024
    risk 0.36cvss 5.6epss 0.00

    MSI Afterburner v4.6.5.16370 is vulnerable to a Kernel Memory Leak vulnerability by triggering the 0x80002040 IOCTL code of the RTCore64.sys driver. The handle to the driver can only be obtained from a high integrity process.

  • CVE-2022-34110MedSep 12, 2022
    risk 0.36cvss 5.5epss 0.00

    An issue in Micro-Star International MSI Feature Navigator v1.0.1808.0901 allows attackers to download arbitrary files regardless of file type or size.

  • CVE-2024-1443MedMar 7, 2024
    risk 0.29cvss 4.4epss 0.00

    MSI Afterburner v4.6.5.16370 is vulnerable to a Denial of Service vulnerability by triggering the 0x80002000 IOCTL code of the RTCore64.sys driver. The handle to the driver can only be obtained from a high integrity process.

  • CVE-2026-6102HigJul 29, 2026
    risk 0.00cvss 7.8epss 0.00

    MSI Center NTIOLib_X64 Origin Validation Error Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MSI Center. An attacker must first obtain the ability to execute low-privileged code on the…

  • CVE-2026-57851HigJul 7, 2026
    risk 0.00cvss 7.8epss 0.00

    MSI Feature Manager contains a local privilege escalation vulnerability in the KernCoreLib64.sys kernel driver that allows any locally logged-on user to perform arbitrary physical memory read/write and unrestricted I/O port operations by accessing exposed IOCTL handlers without…

  • CVE-2026-37452HigJun 25, 2026
    risk 0.00cvss 7.5epss 0.00

    Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensitive information via the MSIAPService.exe component

  • CVE-2026-37454HigJun 25, 2026
    risk 0.00cvss 7.5epss 0.00

    Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensitive information via the 3DES-ECB encryption

  • CVE-2026-37453HigJun 25, 2026
    risk 0.00cvss 7.5epss 0.00

    Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensitive information via the MSI_SERVICE_2 pipe