CVE-2026-82908
largeInteger Overflow in MSI Dragon Center NTIOLib_X64.sys MMIO Handler
CVE-2026-82908 is an integer overflow (CWE-190) in the MmioWritePath function of the NTIOLib_X64.sys kernel driver component (MMIO Write Path Handler) in MSI Dragon Center, exploitable in versions up to and including 2.0.155.0. A local attacker with low privileges can trigger it by manipulating the count/elementSize argument passed to the MMIO write path, causing an integer overflow that corrupts kernel memory. The CVSS 4.0 profile (high confidentiality/integrity/availability across security, system, and safety scopes) indicates an attacker can gain kernel-level control of the affected machine, far beyond the user account they start from. Anyone running an affected Dragon Center version on Windows, typically owners of MSI motherboards, laptops, and other MSI hardware, is affected. The disclosure states an exploit has been made public and could be used, but the flaw is not in CISA KEV, EPSS is very low (0.1% in 30 days, 2nd percentile), and MSI reportedly did not respond to the coordinated disclosure, so no vendor fix is confirmed yet.
What to do: Inventory Windows systems with MSI Dragon Center installed and check whether the version is 2.0.155.0 or earlier and whether the NTIOLib_X64.sys driver is loaded. Because the vendor did not respond to disclosure and no patched release is confirmed in the data, treat an upgrade as 'apply when available' and consider uninstalling Dragon Center or removing the NTIOLib_X64.sys driver on machines that do not need it, while limiting untrusted local accounts on affected systems. Monitor MSI for an updated release and watch for escalation of this flaw given the public exploit.
| MSI Dragon Center | All versions up to and including 2.0.155.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability was found in MSI Dragon Center up to 2.0.155.0. Affected by this vulnerability is the function MmioWritePath in the library NTIOLib_X64.sys of the component MMIO Write Path Handler. Performing a manipulation of the argument count/elementSize results in integer overflow. The attack requires a local approach. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
- Weakness
- CWE-189, CWE-190
- Vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.