MSI manufactures system-optimization and overclocking software for consumer and enthusiast hardware, with vulnerabilities concentrating in products such as Dragon Center, Afterburner, and its feature navigator utilities. The exposure recurs through memory-safety weaknesses including buffer overflows and out-of-bounds writes, alongside information-disclosure flaws typical of privileged system-level software; a meaningful share of these disclosures reach serious severity and tend to acquire public exploit tooling. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Msi over time
Signals from CVEs in this vendor scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-27965CRITICAL The MsIo64.sys driver before 1.1.19.1016 in MSI Dragon Center before 2.0.98.0 has a buffer overflow that allows privilege escalation via a crafted 0x80102040, 0x80102044, 0x8010205 | Mar 5, 2021 | 9.8 | 37 | NO | NO |
CVE-2019-16098HIGH The driver in Micro-Star MSI Afterburner 4.6.2.15658 (aka RTCore64.sys and RTCore32.sys) allows any authenticated user to read and write to arbitrary memory, I/O ports, and MSRs. T | Sep 11, 2019 | 7.8 | 35 | NO | NO |
CVE-2020-17382HIGH The MSI AmbientLink MsIo64 driver 1.0.0.8 has a Buffer Overflow (0x80102040, 0x80102044, 0x80102050,and 0x80102054). | Oct 2, 2020 | 7.8 | 32 | NO | YES |
CVE-2026-37453HIGH Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensitive information via the MSI_SERVICE_2 pipe | Jun 25, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-37454HIGH Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensitive information via the 3DES-ECB encryption | Jun 25, 2026 | 7.5 | 30 | NO | NO |
CVE-2022-31877HIGH An issue in the component MSI.TerminalServer.exe of MSI Center v1.0.41.0 allows attackers to escalate privileges via a crafted TCP packet. | Nov 28, 2022 | 8.8 | 30 | NO | NO |
CVE-2021-32415HIGH EXEMSI MSI Wrapper Versions prior to 10.0.50 and at least since version 6.0.91 will introduce a local privilege escalation vulnerability in installers it creates. | Dec 13, 2022 | 7.8 | 28 | NO | NO |
CVE-2022-34108HIGH An issue in the Feature Navigator of Micro-Star International MSI Feature Nagivator v1.0.1808.0901 allows attackers to cause a Denial of Service (DoS) via a crafted image or video | Sep 12, 2022 | 7.1 | 26 | NO | NO |
CVE-2022-38532HIGH Micro-Star International Co., Ltd MSI Center 1.0.50.0 was discovered to contain a vulnerability in the component C_Features of MSI.CentralServer.exe. This vulnerability allows atta | Sep 19, 2022 | 7.8 | 25 | NO | NO |
CVE-2021-44903HIGH Micro-Star International (MSI) Center Pro <= 2.0.16.0 is vulnerable to multiple Privilege Escalation (LPE/EoP) vulnerabilities in the atidgllk.sys, atillk64.sys, MODAPI.sys, NTIOLi | Feb 4, 2022 | 7.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (21 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Msi.
Media articles that mention a CVE ID that affects a product developed by Msi — matched by CVE ID, not by vendor name.