CVE-2021-27965: Buffer Overflow
Published Mar 5, 2021
·Updated
The MsIo64.sys driver before 1.1.19.1016 in MSI Dragon Center before 2.0.98.0 has a buffer overflow that allows privilege escalation via a crafted 0x80102040, 0x80102044, 0x80102050, or 0x80102054 IOCTL request.
Affected Software
1 affected component
MSI Dragon Center<2.0.98.0
Remediation
Event History
Mar 5, 2021
CVE Published
via MITRE·01:53 AM
Data Sourced
via MITRE·01:53 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-27965?
CVE-2021-27965 has been classified with a high severity level due to its potential for privilege escalation.
2
How do I fix CVE-2021-27965?
To mitigate CVE-2021-27965, users should update the MSI Dragon Center software to version 2.0.98.0 or later.
3
What is the source of the vulnerability in CVE-2021-27965?
The vulnerability in CVE-2021-27965 is caused by a buffer overflow in the MsIo64.sys driver.
4
Which versions of MSI Dragon Center are affected by CVE-2021-27965?
CVE-2021-27965 affects MSI Dragon Center versions prior to 2.0.98.0.
5
What type of attacks can exploit CVE-2021-27965?
CVE-2021-27965 can be exploited through crafted IOCTL requests that are specifically targeted at the affected driver.