A buffer overflow vulnerability exists in the MsIo64.sys driver prior to version 1.1.19.1016, used by MSI Dragon Center before 2.0.98.0. The vulnerability can be triggered by sending specially crafted IOCTL requests (0x80102040, 0x80102044, 0x80102050, or 0x80102054) to the driver, allowing an attacker to overwrite memory and potentially execute code with elevated privileges.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a working local privilege escalation exploit for CVE-2021-27965, targeting the MsIo64.sys driver used in MSI Dragon Center (before version 2.0.98.0, driver before 1.1.19.1016) on Windows. The exploit is implemented in C (exploit.c, exploit.h) and includes custom x64 kernel shellcode (shellcode.asm) that performs token stealing to elevate the current process to SYSTEM privileges. The exploit works by crafting a specially structured input buffer and sending it to the vulnerable driver via DeviceIoControl with IOCTL code 0x80102050, triggering a stack-based buffer overflow. Upon successful exploitation, the shellcode is executed in kernel mode, and a SYSTEM-level command prompt is spawned. The repository includes Visual Studio project files for building the exploit. The attack vector is local, requiring the attacker to execute code on the target system. The main fingerprintable endpoints are the device path (\\.\GLOBALROOT\Device\MsIo) and the use of cmd.exe for privilege escalation demonstration.
This repository contains a proof-of-concept (PoC) exploit for CVE-2021-27965, a local privilege escalation vulnerability in the signed MICSYS MsIo64.sys Windows driver. The exploit (CVE-2021-27965.c) demonstrates how to leverage a stack-based buffer overflow in the driver's IOCTL dispatch routine to achieve arbitrary kernel memory read/write. The exploit works by opening a handle to the vulnerable device (\\.\MsIo), crafting a malicious IOCTL request (notably 0x80102044), and using ROP gadgets to manipulate kernel memory, specifically to leak and copy kernel pointers such as EPROCESS. The included MsIo64.c file is a partial reverse-engineered or reference implementation of the vulnerable driver, showing the insecure IOCTL handling and device creation. The README.md provides a high-level overview of the vulnerability, affected IOCTL codes, and the exploit's purpose. The exploit is a local privilege escalation (LPE) PoC and does not provide a weaponized payload, but it gives the attacker a powerful primitive for further exploitation on affected Windows systems.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.