Description
A vulnerability was found in MSI Dragon Center up to 2.0.155.0. Affected by this vulnerability is the function MmioWritePath in the library NTIOLib_X64.sys of the component MMIO Write Path Handler. Performing a manipulation of the argument count/elementSize results in integer overflow. The attack requires a local approach. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-08-31
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

Affected is the MmioWritePath function in NTIOLib_X64.sys within MSI Dragon Center up to version 2.0.155.0. Malicious manipulation of the argument count or elementSize triggers an integer overflow, which can corrupt memory boundaries or allow arbitrary writes. The described weakness aligns with integer overflow (CWE-189) and arithmetic overflow (CWE-190). Because the vulnerability is local, an attacker who can run code on the system can exploit it without network privileges.

Affected Systems

MSI Dragon Center installers and applications distributed up to and including version 2.0.155.0 are impacted. The vulnerability exists in the NTIOLib_X64.sys component of Dragon Center.

Risk and Exploitability

The CVSS base score of 9.3 places this flaw in the critical range. The EPSS score is not available, but the public disclosure of an exploit indicates that attackers are already able to leverage this weakness. The flaw is not yet listed under CISA's KEV catalog, yet the local nature of the attack combined with the high severity suggests that any machine with Dragon Center installed and a local account possessing elevated privileges should be treated as high risk. An attacker who accesses the local system can trigger the overflow and potentially gain administrator privileges or execute arbitrary code.

Generated by OpenCVE AI on August 31, 2026 at 21:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade MSI Dragon Center to the latest patched release that addresses the MmioWritePath integer overflow
  • If an upgrade is not immediately possible, restrict Dragon Center from running with elevated privileges or remove administrative rights for local users who need it
  • Enable Windows host hardening features such as Address Space Layout Randomization (ASLR) and Data Execution Prevention (DEP) to reduce the effectiveness of local exploitation attempts

Generated by OpenCVE AI on August 31, 2026 at 21:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 31 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in MSI Dragon Center up to 2.0.155.0. Affected by this vulnerability is the function MmioWritePath in the library NTIOLib_X64.sys of the component MMIO Write Path Handler. Performing a manipulation of the argument count/elementSize results in integer overflow. The attack requires a local approach. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title MSI Dragon Center MMIO Write Path NTIOLib_X64.sys MmioWritePath integer overflow
First Time appeared Msi
Msi dragon Center
Weaknesses CWE-189
CWE-190
CPEs cpe:2.3:a:msi:dragon_center:*:*:*:*:*:*:*:*
Vendors & Products Msi
Msi dragon Center
References
Metrics cvssV2_0

{'score': 6.8, 'vector': 'AV:L/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


Subscriptions

Msi Dragon Center
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-01T13:57:31.239Z

Reserved: 2026-08-31T10:11:41.678Z

Link: CVE-2026-82908

cve-icon Vulnrichment

Updated: 2026-09-01T13:57:13.631Z

cve-icon NVD

Status : Deferred

Published: 2026-08-31T21:17:54.503

Modified: 2026-09-01T20:47:54.130

Link: CVE-2026-82908

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T22:15:04Z

Weaknesses