Privilege Escalation Vulnerabilities in MSI App Player by Micro-Star International
CVE-2021-44900

7.8HIGH

Key Information:

Vendor

Msi

Vendor
CVE Published:
4 February 2022

What is CVE-2021-44900?

Micro-Star International's MSI App Player versions up to 4.280.1.6309 are susceptible to multiple privilege escalation vulnerabilities. These issues stem from flaws in the NTIOLib_X64.sys and BstkDrv_msi2.sys driver components, which can be exploited through the sending of specific IOCTL requests. Successful exploitation could allow an attacker to gain elevated privileges on the affected system, potentially leading to unauthorized access to sensitive data or system functionalities.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2021-44900 : Privilege Escalation Vulnerabilities in MSI App Player by Micro-Star International