Skip to main content

msi lpe poc

0
Medium
Published: 09/12/2026 (09/12/2026, 18:52:36 UTC)
Source: Reddit ExploitDev

Description

An unauthenticated local privilege escalation vulnerability exists in the MODAPI.sys kernel driver installed by MSI Dragon Center 2.0.155.0. The driver exposes a device object with a security descriptor allowing any local user to open it without administrative privileges or UAC. This enables arbitrary read and write access to Model-Specific Registers (MSRs), including the IA32_LSTAR MSR, which controls the CPU syscall entry point. By overwriting IA32_LSTAR, an attacker can execute arbitrary code at kernel privilege level (CPL0), bypassing SMEP via gadgets found in the kernel image. The exploit was tested successfully on Windows 10 x64 22H2 (build 19045.6456) from a standard user account. The vulnerability was reported to MSI on 2026-06-21 and a fix has been verified.

Reddit Discussion

r/ExploitDev·posted by u/nanaynunay
00

hi all, this is my repo, support pls https://github.com/mein-0/LolModapi

Links cited in this discussion

Affected software

Affected versions
=2.0.155.0

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/12/2026, 22:17:09 UTC

Technical Analysis

The MODAPI.sys driver installed by MSI Dragon Center 2.0.155.0 contains a local privilege escalation vulnerability due to an insecure device object security descriptor that permits any local user to open a handle without admin rights. This handle allows unrestricted read and write access to MSRs, including IA32_LSTAR, which defines the CPU's syscall entry address. An attacker can read IA32_LSTAR to locate ntoskrnl!KiSystemCall64, parse the kernel image to find gadgets to disable SMEP, and overwrite IA32_LSTAR to redirect syscalls to attacker-controlled shellcode running at kernel privilege. The exploit requires no race conditions or heap grooming and works reliably on Windows 10 x64 22H2. The vulnerability was responsibly disclosed to MSI and a patch has been confirmed.

Potential Impact

An attacker with local user access can gain kernel-level code execution by exploiting this vulnerability. This allows full system compromise, including privilege escalation to SYSTEM. The exploit bypasses SMEP protections and requires no user interaction beyond running the exploit as a normal user. Systems with MSI Dragon Center 2.0.155.0 installed and the vulnerable MODAPI.sys driver loaded are affected.

Mitigation Recommendations

A fix has been verified by MSI following responsible disclosure on 2026-06-21. Users should apply the official MSI Dragon Center update that addresses this vulnerability. Until patched, restricting local user access to affected systems and uninstalling MSI Dragon Center may mitigate risk. No other mitigations are documented.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
ExploitDev+pwned+hacking
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Newsworthiness Assessment
{"score":35,"reasons":["external_link","established_author","recent_news"],"isNewsworthy":true}
Has External Source
true
Trusted Domain
false

Threat ID: 6aa5cf6055bf5e2cf5cf9c54

Added to database: 09/12/2026, 22:17:04 UTC

Last enriched: 09/12/2026, 22:17:09 UTC

Last updated: 09/13/2026, 04:01:25 UTC

Views: 10

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses