CVE-2020-13149 describes a privilege escalation vulnerability in MSI Dragon Center versions prior to 2.6.2003.2401, affecting MSI Gaming laptops. Weak permissions on the "%PROGRAMDATA%\MSI\Dragon Center" folder allow a local authenticated attacker to overwrite system files. This can be achieved by modifying the Recommended App binary in App.json or by mounting an RPC Control directory within the vulnerable path. The vulnerability has a CVSSv3.1 score of 7.8 (High), indicating a significant impact with high confidentiality, integrity, and availability risks. The attack requires local access and low privileges, but no user interaction is needed. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. The vulnerability has received minimal community discussion and media coverage, suggesting low public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.6.2003.2401CPE matchmatch criteria | cpe:2.3:a:msi:dragon_center:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.