Impact
Affected is the MmioWritePath function in NTIOLib_X64.sys within MSI Dragon Center up to version 2.0.155.0. Malicious manipulation of the argument count or elementSize triggers an integer overflow, which can corrupt memory boundaries or allow arbitrary writes. The described weakness aligns with integer overflow (CWE-189) and arithmetic overflow (CWE-190). Because the vulnerability is local, an attacker who can run code on the system can exploit it without network privileges.
Affected Systems
MSI Dragon Center installers and applications distributed up to and including version 2.0.155.0 are impacted. The vulnerability exists in the NTIOLib_X64.sys component of Dragon Center.
Risk and Exploitability
The CVSS base score of 9.3 places this flaw in the critical range. The EPSS score is not available, but the public disclosure of an exploit indicates that attackers are already able to leverage this weakness. The flaw is not yet listed under CISA's KEV catalog, yet the local nature of the attack combined with the high severity suggests that any machine with Dragon Center installed and a local account possessing elevated privileges should be treated as high risk. An attacker who accesses the local system can trigger the overflow and potentially gain administrator privileges or execute arbitrary code.
OpenCVE Enrichment