Description
MSI Center NTIOLib_X64 Origin Validation Error Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MSI Center. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

The specific flaw exists within the NTIOLib_X64.sys driver. The issue results from insufficient validation of the origin of commands. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-28935.
Published: 2026-07-29
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from insufficient validation of the origin of commands within the NTIOLib_X64.sys driver used by MSI Center. The flaw permits a local attacker to gain SYSTEM‑level privileges by tricking the driver into executing commands that originate from an untrusted source. If successful, the attacker can execute arbitrary code with full system rights, compromising the confidentiality, integrity, and availability of the affected machine.

Affected Systems

The flaw affects installations of MSI Center from MSI. The vendor and product name is MSI Center. No specific affected version information has been disclosed in the advisory.

Risk and Exploitability

With a CVSS score of 7.8 the vulnerability is considered High severity, and the EPSS score of less than 1% indicates that the likelihood of exploitation is very low but not negligible. The vulnerability is not listed in the CISA KEV catalog. The attack requires local execution of low‑privileged code as a precondition, meaning an attacker must already have some local presence to trigger the escalation.

Generated by OpenCVE AI on August 3, 2026 at 12:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest MSI Center update or patch provided by the vendor to fix the NTIOLib_X64 driver validation flaw.
  • Restrict local accounts and enforce least privilege to minimize the chance of an attacker executing low‑privileged code on the target system.
  • If a patch is not available, consider removing or disabling the NTIOLib_X64.sys driver or uninstalling MSI Center components that rely on it until a fix is released.

Generated by OpenCVE AI on August 3, 2026 at 12:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 29 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Msi
Msi center
Vendors & Products Msi
Msi center

Wed, 29 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Description MSI Center NTIOLib_X64 Origin Validation Error Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MSI Center. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the NTIOLib_X64.sys driver. The issue results from insufficient validation of the origin of commands. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-28935.
Title MSI Center NTIOLib_X64 Origin Validation Error Local Privilege Escalation Vulnerability
Weaknesses CWE-346
References
Metrics cvssV3_0

{'score': 7.8, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: zdi

Published:

Updated: 2026-07-31T03:56:14.448Z

Reserved: 2026-04-11T00:19:18.083Z

Link: CVE-2026-6102

cve-icon Vulnrichment

Updated: 2026-07-30T13:42:22.192Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-29T20:17:12.980

Modified: 2026-07-31T04:17:24.730

Link: CVE-2026-6102

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T13:00:07Z

Weaknesses