msi lpe poc
An unauthenticated local privilege escalation vulnerability exists in the MODAPI.sys kernel driver installed by MSI Dragon Center 2.0.155.0. The driver exposes a device object with a security descriptor allowing any local user to open it without administrative privileges or UAC. This enables arbitrary read and write access to Model-Specific Registers (MSRs), including the IA32_LSTAR MSR, which controls the CPU syscall entry point. By overwriting IA32_LSTAR, an attacker can execute arbitrary code at kernel privilege level (CPL0), bypassing SMEP via gadgets found in the kernel image. The exploit was tested successfully on Windows 10 x64 22H2 (build 19045.6456) from a standard user account. The vulnerability was reported to MSI on 2026-06-21 and a fix has been verified.
AI Analysis
Technical Summary
The MODAPI.sys driver installed by MSI Dragon Center 2.0.155.0 contains a local privilege escalation vulnerability due to an insecure device object security descriptor that permits any local user to open a handle without admin rights. This handle allows unrestricted read and write access to MSRs, including IA32_LSTAR, which defines the CPU's syscall entry address. An attacker can read IA32_LSTAR to locate ntoskrnl!KiSystemCall64, parse the kernel image to find gadgets to disable SMEP, and overwrite IA32_LSTAR to redirect syscalls to attacker-controlled shellcode running at kernel privilege. The exploit requires no race conditions or heap grooming and works reliably on Windows 10 x64 22H2. The vulnerability was responsibly disclosed to MSI and a patch has been confirmed.
Potential Impact
An attacker with local user access can gain kernel-level code execution by exploiting this vulnerability. This allows full system compromise, including privilege escalation to SYSTEM. The exploit bypasses SMEP protections and requires no user interaction beyond running the exploit as a normal user. Systems with MSI Dragon Center 2.0.155.0 installed and the vulnerable MODAPI.sys driver loaded are affected.
Mitigation Recommendations
A fix has been verified by MSI following responsible disclosure on 2026-06-21. Users should apply the official MSI Dragon Center update that addresses this vulnerability. Until patched, restricting local user access to affected systems and uninstalling MSI Dragon Center may mitigate risk. No other mitigations are documented.
msi lpe poc
Description
An unauthenticated local privilege escalation vulnerability exists in the MODAPI.sys kernel driver installed by MSI Dragon Center 2.0.155.0. The driver exposes a device object with a security descriptor allowing any local user to open it without administrative privileges or UAC. This enables arbitrary read and write access to Model-Specific Registers (MSRs), including the IA32_LSTAR MSR, which controls the CPU syscall entry point. By overwriting IA32_LSTAR, an attacker can execute arbitrary code at kernel privilege level (CPL0), bypassing SMEP via gadgets found in the kernel image. The exploit was tested successfully on Windows 10 x64 22H2 (build 19045.6456) from a standard user account. The vulnerability was reported to MSI on 2026-06-21 and a fix has been verified.
Reddit Discussion
hi all, this is my repo, support pls https://github.com/mein-0/LolModapi
Links cited in this discussion
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The MODAPI.sys driver installed by MSI Dragon Center 2.0.155.0 contains a local privilege escalation vulnerability due to an insecure device object security descriptor that permits any local user to open a handle without admin rights. This handle allows unrestricted read and write access to MSRs, including IA32_LSTAR, which defines the CPU's syscall entry address. An attacker can read IA32_LSTAR to locate ntoskrnl!KiSystemCall64, parse the kernel image to find gadgets to disable SMEP, and overwrite IA32_LSTAR to redirect syscalls to attacker-controlled shellcode running at kernel privilege. The exploit requires no race conditions or heap grooming and works reliably on Windows 10 x64 22H2. The vulnerability was responsibly disclosed to MSI and a patch has been confirmed.
Potential Impact
An attacker with local user access can gain kernel-level code execution by exploiting this vulnerability. This allows full system compromise, including privilege escalation to SYSTEM. The exploit bypasses SMEP protections and requires no user interaction beyond running the exploit as a normal user. Systems with MSI Dragon Center 2.0.155.0 installed and the vulnerable MODAPI.sys driver loaded are affected.
Mitigation Recommendations
A fix has been verified by MSI following responsible disclosure on 2026-06-21. Users should apply the official MSI Dragon Center update that addresses this vulnerability. Until patched, restricting local user access to affected systems and uninstalling MSI Dragon Center may mitigate risk. No other mitigations are documented.
Technical Details
- Source Type
- Subreddit
- ExploitDev+pwned+hacking
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Newsworthiness Assessment
- {"score":35,"reasons":["external_link","established_author","recent_news"],"isNewsworthy":true}
- Has External Source
- true
- Trusted Domain
- false
Threat ID: 6aa5cf6055bf5e2cf5cf9c54
Added to database: 09/12/2026, 22:17:04 UTC
Last enriched: 09/12/2026, 22:17:09 UTC
Last updated: 09/13/2026, 04:01:25 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.