CVE-2026-57851
MSI Feature Manager contains a local privilege escalation vulnerability in the KernCoreLib64.sys kernel driver that allows any locally logged-on user to perform arbitrary physical memory read/write and unrestricted I/O port operations by accessing exposed IOCTL handlers without administrator privileges. Attackers can exploit the accessible device object through IOCTL handlers to manipulate kernel objects, tamper with kernel-mode callbacks, bypass Protected Process Light protections, and disable security software.
Published:Jul 7, 2026
Last Modified:Jul 28, 2026
EPS:Jul 7, 2026
EPSS Score:0.0017
CVSS Score:7.8
Affected Products
Vendor
Product
Action
Vendor
Icu-project
Product
International Components For Unicode
Icu-project
International Components For Unicode
Vendor
Msi
Product
Kerncorelib64.sys
Msi
Kerncorelib64.sys
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
