QID 377637

Date Published: 2022-10-18

QID 377637: Micro-Star MSI Afterburner Privilege Escalation Vulnerability

MSI Afterburner is the most used graphics card software that gives you complete control, lets you monitor your hardware in real-time.

The driver in Micro-Star MSI Afterburner 4.6.2.15658 (aka RTCore64.sys and RTCore32.sys) allows any authenticated user to read and write to arbitrary memory, I/O ports, and MSRs.

Affected Version:
Micro-Star MSI Afterburner 4.6.2.15658

QID Detection Logic (Authenticated):
Windows: QID flags if vulnerable version found using registry path "HKLM\SOFTWARE\MSI\Afterburner" or "HKLM\SOFTWARE\WOW6432Node\MSI\Afterburner"

Successful exploitation of this vulnerability may allow an low privileged attacker to escalate privileges, code execution under high privileges, and information disclosure.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 7.2 severity.
  • Solution
    Please connect with vendor MSI Afterburner for patch information.
    Vendor References

    CVEs related to QID 377637

    Software Advisories
    Advisory ID Software Component Link
    MSI Afterburner Official Page URL Logo www.msi.com/Landing/afterburner/graphics-cards