MSI records
22 published records for vendor msi.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 4.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-123 Write-what-where Condition1
- CWE-125 Out-of-bounds Read1
- CWE-276 Incorrect Default Permissions1
- CWE-345 Insufficient Verification of Data Authenticity1
- CWE-404 Improper Resource Shutdown or Release1
The weakness classes this vendor ships most often: where to look.
CWEAll records
22 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
43Plan | CVE-2021-27965Proof of concept | The MsIo64.sys driver before 1.1.19.1016 in MSI Dragon Center before 2.0.98.0 has a buffer overflow that allows privilege escalation via a cmsi · dragon center · CWE-120 | Critical9.8 | — | 11.8% | Mar 4, 2021 |
37Monitor | CVE-2019-16098Proof of concept | The driver in Micro-Star MSI Afterburner 4.6.2.15658 (aka RTCore64.sys and RTCore32.sys) allows any authenticated user to read and write to msi · afterburner · CWE-125 | High7.8 | — | 19.8% | Sep 11, 2019 |
35Monitor | CVE-2022-31877No exploit | An issue in the component MSI.TerminalServer.exe of MSI Center v1.0.41.0 allows attackers to escalate privileges via a crafted TCP packet.msi · center · CWE-345 | High8.8 | — | 0.4% | Nov 28, 2022 |
32Monitor | CVE-2020-17382Proof of concept | The MSI AmbientLink MsIo64 driver 1.0.0.8 has a Buffer Overflow (0x80102040, 0x80102044, 0x80102050,and 0x80102054).msi · ambientlink mslo64 firmware · CWE-787 | High7.8 | — | 2.1% | Oct 2, 2020 |
32Monitor | CVE-2024-36877Proof of concept | Micro-Star International Z-series motherboards (Z590, Z490, and Z790) and B-series motherboards (B760, B560, B660, and B460) with firmware 7CWE-123 | High8.2 | — | 0.7% | Aug 12, 2024 |
31Monitor | CVE-2021-29337Proof of concept | MODAPI.sys in MSI Dragon Center 2.0.104.0 allows low-privileged users to access kernel memory and potentially escalate privileges via a crafmsi · dragon center | High7.8 | — | 0.8% | Jun 21, 2021 |
31Monitor | CVE-2022-38532Proof of concept | Micro-Star International Co., Ltd MSI Center 1.0.50.0 was discovered to contain a vulnerability in the component C_Features of MSI.CentralSemsi · center | High7.8 | — | 0.5% | Sep 19, 2022 |
31Monitor | CVE-2021-44901No exploit | Micro-Star International (MSI) Dragon Center <= 2.0.116.0 is vulnerable to multiple Privilege Escalation (LPE/EoP) vulnerabilities in the atmsi · dragon center | High7.8 | — | 0.5% | Feb 4, 2022 |
31Monitor | CVE-2020-13149No exploit | Weak permissions on the "%PROGRAMDATA%\MSI\Dragon Center" folder in Dragon Center before 2.6.2003.2401, shipped with Micro-Star MSI Gaming lmsi · dragon center · CWE-276 | High7.8 | — | 0.4% | May 18, 2020 |
31Monitor | CVE-2021-44899No exploit | Micro-Star International (MSI) Center <= 1.0.31.0 is vulnerable to multiple Privilege Escalation vulnerabilities in the atidgllk.sys, atillkmsi · center | High7.8 | — | 0.4% | Feb 4, 2022 |
31Monitor | CVE-2021-44903No exploit | Micro-Star International (MSI) Center Pro <= 2.0.16.0 is vulnerable to multiple Privilege Escalation (LPE/EoP) vulnerabilities in the atidglmsi · center pro | High7.8 | — | 0.3% | Feb 4, 2022 |
31Monitor | CVE-2021-44900No exploit | Micro-Star International (MSI) App Player <= 4.280.1.6309 is vulnerable to multiple Privilege Escalation (LPE/EoP) vulnerabilities in the NTmsi · app player | High7.8 | — | 0.3% | Feb 4, 2022 |
31Monitor | CVE-2021-32415No exploit | EXEMSI MSI Wrapper Versions prior to 10.0.50 and at least since version 6.0.91 will introduce a local privilege escalation vulnerability in msi · wrapper | High7.8 | — | 0.2% | Dec 13, 2022 |
31Monitor | CVE-2024-3745No exploit | MSI Afterburner v4.6.6.16381 Beta 3 - ACL Bypassmsi · msi afterburner · CWE-863 | High7.8 | — | 0.2% | May 18, 2024 |
30Monitor | CVE-2026-37453No exploit | Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensitive information via msi · center · CWE-200 | High7.5 | — | 0.5% | Jun 25, 2026 |
30Monitor | CVE-2026-37454No exploit | Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensitive information via msi · center · CWE-200 | High7.5 | — | 0.3% | Jun 25, 2026 |
28Monitor | CVE-2022-34108No exploit | An issue in the Feature Navigator of Micro-Star International MSI Feature Nagivator v1.0.1808.0901 allows attackers to cause a Denial of Sermsi · micro-star international feature navigator | High7.1 | — | 0.3% | Sep 12, 2022 |
28Monitor | CVE-2022-34109No exploit | An issue in Micro-Star International MSI Feature Navigator v1.0.1808.0901 allows attackers to write arbitrary files to the directory \PromoPmsi · micro-star international feature navigator | High7.1 | — | 0.3% | Sep 12, 2022 |
27Monitor | CVE-2024-12227Proof of concept | MSI Dragon Center IOCTL NTIOLib_X64.sys MmUnMapIoSpace null pointer dereferencemsi · dragon center · CWE-404 | Medium6.8 | — | 0.2% | Dec 5, 2024 |
22Monitor | CVE-2022-34110No exploit | An issue in Micro-Star International MSI Feature Navigator v1.0.1808.0901 allows attackers to download arbitrary files regardless of file tymsi · micro-star international feature navigator | Medium5.5 | — | 0.3% | Sep 12, 2022 |
17Monitor | CVE-2024-1460No exploit | MSI Afterburner v4.6.5.16370 - Kernel Memory Leakmsi · afterburner · CWE-200 | Medium4.4 | — | 0.2% | Mar 6, 2024 |
17Monitor | CVE-2024-1443No exploit | MSI Afterburner v4.6.5.16370 - Denial of Servicemsi · afterburner · CWE-476 | Medium4.4 | — | 0.2% | Mar 6, 2024 |
- CVE-2021-2796543Plan
The MsIo64.sys driver before 1.1.19.1016 in MSI Dragon Center before 2.0.98.0 has a buffer overflow that allows privilege escalation via a c
CriticalCVSS 9.8Proof of conceptEPSS 12%msi · dragon centerMar 4, 2021
- CVE-2019-1609837Monitor
The driver in Micro-Star MSI Afterburner 4.6.2.15658 (aka RTCore64.sys and RTCore32.sys) allows any authenticated user to read and write to
HighCVSS 7.8Proof of conceptEPSS 20%msi · afterburnerSep 11, 2019
- CVE-2022-3187735Monitor
An issue in the component MSI.TerminalServer.exe of MSI Center v1.0.41.0 allows attackers to escalate privileges via a crafted TCP packet.
HighCVSS 8.8No exploitEPSS 0%msi · centerNov 28, 2022
- CVE-2020-1738232Monitor
The MSI AmbientLink MsIo64 driver 1.0.0.8 has a Buffer Overflow (0x80102040, 0x80102044, 0x80102050,and 0x80102054).
HighCVSS 7.8Proof of conceptEPSS 2%msi · ambientlink mslo64 firmwareOct 2, 2020
- CVE-2024-3687732Monitor
Micro-Star International Z-series motherboards (Z590, Z490, and Z790) and B-series motherboards (B760, B560, B660, and B460) with firmware 7
HighCVSS 8.2Proof of conceptEPSS 1%Aug 12, 2024
- CVE-2021-2933731Monitor
MODAPI.sys in MSI Dragon Center 2.0.104.0 allows low-privileged users to access kernel memory and potentially escalate privileges via a craf
HighCVSS 7.8Proof of conceptEPSS 1%msi · dragon centerJun 21, 2021
- CVE-2022-3853231Monitor
Micro-Star International Co., Ltd MSI Center 1.0.50.0 was discovered to contain a vulnerability in the component C_Features of MSI.CentralSe
HighCVSS 7.8Proof of conceptEPSS 0%msi · centerSep 19, 2022
- CVE-2021-4490131Monitor
Micro-Star International (MSI) Dragon Center <= 2.0.116.0 is vulnerable to multiple Privilege Escalation (LPE/EoP) vulnerabilities in the at
HighCVSS 7.8No exploitEPSS 0%msi · dragon centerFeb 4, 2022
- CVE-2020-1314931Monitor
Weak permissions on the "%PROGRAMDATA%\MSI\Dragon Center" folder in Dragon Center before 2.6.2003.2401, shipped with Micro-Star MSI Gaming l
HighCVSS 7.8No exploitEPSS 0%msi · dragon centerMay 18, 2020
- CVE-2021-4489931Monitor
Micro-Star International (MSI) Center <= 1.0.31.0 is vulnerable to multiple Privilege Escalation vulnerabilities in the atidgllk.sys, atillk
HighCVSS 7.8No exploitEPSS 0%msi · centerFeb 4, 2022
- CVE-2021-4490331Monitor
Micro-Star International (MSI) Center Pro <= 2.0.16.0 is vulnerable to multiple Privilege Escalation (LPE/EoP) vulnerabilities in the atidgl
HighCVSS 7.8No exploitEPSS 0%msi · center proFeb 4, 2022
- CVE-2021-4490031Monitor
Micro-Star International (MSI) App Player <= 4.280.1.6309 is vulnerable to multiple Privilege Escalation (LPE/EoP) vulnerabilities in the NT
HighCVSS 7.8No exploitEPSS 0%msi · app playerFeb 4, 2022
- CVE-2021-3241531Monitor
EXEMSI MSI Wrapper Versions prior to 10.0.50 and at least since version 6.0.91 will introduce a local privilege escalation vulnerability in
HighCVSS 7.8No exploitEPSS 0%msi · wrapperDec 13, 2022
- CVE-2024-374531Monitor
MSI Afterburner v4.6.6.16381 Beta 3 - ACL Bypass
HighCVSS 7.8No exploitEPSS 0%msi · msi afterburnerMay 18, 2024
- CVE-2026-3745330Monitor
Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensitive information via
HighCVSS 7.5No exploitEPSS 1%msi · centerJun 25, 2026
- CVE-2026-3745430Monitor
Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensitive information via
HighCVSS 7.5No exploitEPSS 0%msi · centerJun 25, 2026
- CVE-2022-3410828Monitor
An issue in the Feature Navigator of Micro-Star International MSI Feature Nagivator v1.0.1808.0901 allows attackers to cause a Denial of Ser
HighCVSS 7.1No exploitEPSS 0%msi · micro-star international feature navigatorSep 12, 2022
- CVE-2022-3410928Monitor
An issue in Micro-Star International MSI Feature Navigator v1.0.1808.0901 allows attackers to write arbitrary files to the directory \PromoP
HighCVSS 7.1No exploitEPSS 0%msi · micro-star international feature navigatorSep 12, 2022
- CVE-2024-1222727Monitor
MSI Dragon Center IOCTL NTIOLib_X64.sys MmUnMapIoSpace null pointer dereference
MediumCVSS 6.8Proof of conceptEPSS 0%msi · dragon centerDec 5, 2024
- CVE-2022-3411022Monitor
An issue in Micro-Star International MSI Feature Navigator v1.0.1808.0901 allows attackers to download arbitrary files regardless of file ty
MediumCVSS 5.5No exploitEPSS 0%msi · micro-star international feature navigatorSep 12, 2022
- CVE-2024-146017Monitor
MSI Afterburner v4.6.5.16370 - Kernel Memory Leak
MediumCVSS 4.4No exploitEPSS 0%msi · afterburnerMar 6, 2024
- CVE-2024-144317Monitor
MSI Afterburner v4.6.5.16370 - Denial of Service
MediumCVSS 4.4No exploitEPSS 0%msi · afterburnerMar 6, 2024