Privilege Escalation Flaw in Dragon Center by Micro-Star MSI
CVE-2020-13149
7.8HIGH
What is CVE-2020-13149?
The Dragon Center application, used by Micro-Star MSI Gaming laptops, suffers from a vulnerability due to weak permissions on the '%PROGRAMDATA%\MSI\Dragon Center' folder. This issue affects versions prior to 2.6.2003.2401 and allows local authenticated users to overwrite critical system files, potentially leading to escalated privileges. Attackers can exploit this flaw by modifying the Recommended App binary within App.json or by setting up an RPC Control directory using parts of the '%PROGRAMDATA%' path.