← Back to overview

A vulnerability has been identified in MSI Dragon Center up to version 2.0.155.0, specifically in the MmioWritePath function within the NTIOLib_X64.sys library. The flaw resides in the MMIO Write Path Handler component, where manipulation of the count/elementSize arguments leads to an integer overflow condition. The vulnerability requires local access to exploit, limiting its attack surface but not eliminating risk for multi-user or shared systems. A public exploit has been released, increasing the likelihood of active exploitation. The vendor was notified prior to public disclosure but did not respond, leaving users without an official patch or mitigation guidance. This unpatched status, combined with public exploit availability, raises the overall risk level significantly.

Affected products

  • MSI Dragon Center up to 2.0.155.0
  • NTIOLib_X64.sys

Related CVE's

  • CVE-2026-82908

Categories

  • Operating Systems
  • Zero-Day Vulnerabilities