PT-2021-4749 · Msi · Msi Dragon Center

Downwithup

+1

·

Published

2021-06-21

·

Updated

2022-07-12

·

CVE-2021-29337

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MSI Dragon Center version 2.0.104.0
Description The issue is related to the MODAPI.sys driver in the MSI Dragon Center software, which allows low-privileged users to access kernel memory. This could potentially enable an attacker to escalate their privileges. The vulnerability can be exploited via a crafted IOCTL 0x9c406104 call, which provides the MmMapIoSpace feature for mapping physical memory.
Recommendations For MSI Dragon Center version 2.0.104.0, consider disabling the MODAPI.sys driver as a temporary workaround until a patch is available. Restrict access to the IOCTL 0x9c406104 call to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-05465
CVE-2021-29337

Affected Products

Msi Dragon Center