CVE-2026-57851 Details
Description
MSI Feature Manager contains a local privilege escalation vulnerability in the KernCoreLib64.sys kernel driver that allows any locally logged-on user to perform arbitrary physical memory read/write and unrestricted I/O port operations by accessing exposed IOCTL handlers without administrator privileges. Attackers can exploit the accessible device object through IOCTL handlers to manipulate kernel objects, tamper with kernel-mode callbacks, bypass Protected Process Light protections, and disable security software.
A local privilege escalation vulnerability has been identified in the MSI Feature Manager's KernCoreLib64.sys kernel driver. This vulnerability allows any locally logged-on user to perform arbitrary read and write operations on physical memory, as well as unrestricted I/O port operations. The issue arises from exposed IOCTL handlers that can be accessed without administrator privileges. Exploitation of this vulnerability could enable attackers to manipulate kernel objects, interfere with kernel-mode callbacks, bypass Protected Process Light protections, and disable security software.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 7, 2026CISA-ADP
Assessed Jul 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/readmsr/MSI_FeatureManager_CVE | [email protected] | Source Code |
| https://www.vulncheck.com/advisories/msi-gamegaraj-kerncorelib64-sys-privilege-escalation-via-ioctl-handlers | [email protected] | AdvisoryExploitRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-782 | Exposed IOCTL with Insufficient Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| MSI Feature Manager | KernCoreLib64.sys |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 8, 2026 | CVE Modified | [email protected] |
| Jul 7, 2026 | CVE Modified | CISA-ADP |
| Jul 7, 2026 | New CVE Received | [email protected] |
Volerion