Impact
The KernCoreLib64.sys kernel driver in MSI Feature Manager contains a flaw that allows any user logged on locally to invoke exposed IOCTL handlers, read and write arbitrary physical memory, and perform unrestricted I/O port operations. This improper access control flaw (CWE-782) grants kernel‑level privileges, enabling attackers to manipulate kernel objects, tamper with kernel‑mode callbacks, bypass Protected Process Light protections, and disable security software, effectively compromising system integrity and confidentiality.
Affected Systems
The vulnerability affects the KernCoreLib64.sys driver distributed by Micro‑Star International as part of its Feature Manager package. No specific driver revisions or release dates are disclosed, so any installation that includes the driver is potentially exposed.
Risk and Exploitability
The CVSS score of 8.5 places the vulnerability in the high‑severity category, but the EPSS score of less than 1% indicates that public exploitation is currently rare or undocumented. The flaw permits local privilege escalation without requiring administrator rights, so the attack surface is limited to users who can run software on the system. The vulnerability is not listed in CISA’s KEV catalog, yet the ability to manipulate kernel memory and bypass core security mechanisms warrants prompt evaluation and remediation.
OpenCVE Enrichment