Impact
The vulnerability arises from insufficient validation of the origin of commands within the NTIOLib_X64.sys driver used by MSI Center. The flaw permits a local attacker to gain SYSTEM‑level privileges by tricking the driver into executing commands that originate from an untrusted source. If successful, the attacker can execute arbitrary code with full system rights, compromising the confidentiality, integrity, and availability of the affected machine.
Affected Systems
The flaw affects installations of MSI Center from MSI. The vendor and product name is MSI Center. No specific affected version information has been disclosed in the advisory.
Risk and Exploitability
With a CVSS score of 7.8 the vulnerability is considered High severity, and the EPSS score of less than 1% indicates that the likelihood of exploitation is very low but not negligible. The vulnerability is not listed in the CISA KEV catalog. The attack requires local execution of low‑privileged code as a precondition, meaning an attacker must already have some local presence to trigger the escalation.
OpenCVE Enrichment