A buffer overflow vulnerability exists in the MSI AmbientLink MsIo64 driver version 1.0.0.8. The vulnerability is triggered by specific IOCTL codes (0x80102040, 0x80102044, 0x80102050, and 0x80102054), which do not properly validate user-supplied input, leading to a buffer overflow condition in the kernel-mode driver.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository contains a single Windows local privilege escalation exploit (CVE-2020-17382) plus a README. - Structure: - CVE-2020-17382.c: Standalone C exploit for Windows 10 x64 2004 build 19041.264. - README.md: Notes about required environment (no KVA Shadow / no VBS) and references. - Purpose and flow: 1) Opens a handle to the MSI Ambient Link driver device \\.\MsIo. 2) Locates the kernel base address of ntoskrnl.exe via EnumDeviceDrivers/GetDeviceDriverBaseNameA. 3) Allocates RWX memory and copies in embedded x64 token-stealing shellcode; patches two bytes with the current PID. 4) Builds a small ROP chain using hardcoded ntoskrnl.exe gadget offsets (e.g., pop rcx; ret, mov cr4, ecx; ret, wbinvd; ret, add rsp, 0x08; ret) to adjust CR4 and pivot into the shellcode. 5) Triggers the vulnerability by calling DeviceIoControl with IOCTL 0x80102040 and a crafted 128-byte input buffer containing the ROP chain. 6) On success, it prints a message and launches a command prompt (start cmd.exe), intended to run as SYSTEM. - Notable characteristics: - Highly version/offset dependent: ROP gadget addresses are computed as kernel_base + constant offsets, making it specific to the stated build unless adapted. - No network functionality; attack vector is purely local via a vulnerable kernel driver IOCTL.
This repository provides proof-of-concept (PoC) exploits for CVE-2020-17382, a kernel stack-based buffer overflow in the MSI Ambient Link driver (MsIo). The repository contains two main exploit files: one for Windows 10 1709 (written in C) and one for Windows 7 x64 SP1 (written in Python). Both exploits work by opening a handle to the vulnerable driver device (\\.\MsIo) and sending a specially crafted buffer via DeviceIoControl to trigger the buffer overflow. The payload is custom x64 shellcode that performs token stealing, replacing the current process's token with that of the SYSTEM process, thereby granting SYSTEM privileges. On Windows 10, the exploit launches a SYSTEM shell (cmd.exe) upon success. The exploits require local access and the ability to interact with the driver. The repository is well-structured, with clear separation for each target OS version, and includes a README with usage information and references.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.