PT-2026-56209 · Msi · Msi Feature Manager

·

CVE-2026-57851

·

Published

2026-07-07

·

Updated

2026-07-10

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MSI Feature Manager (affected versions not specified)
Description A local privilege escalation issue exists in the KernCoreLib64.sys kernel driver. A locally logged-on user can perform arbitrary physical memory read/write and unrestricted I/O port operations by accessing exposed IOCTL (Input/Output Control) handlers without administrator privileges. This allows attackers to manipulate kernel objects, tamper with kernel-mode callbacks, bypass Protected Process Light (PPL) protections, and disable security software.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57851

Affected Products

Msi Feature Manager