A write-what-where condition exists in the SW handler for SMI 0xE3 in the firmware of Micro-Star International (MSI) Z-series (Z590, Z490, Z790) and B-series (B760, B560, B660, B460) motherboards, affecting firmware versions 7D25v14, 7D25v17 to 7D25v19, and 7D25v1A to 7D25v1H. The vulnerability impacts motherboards with Intel 300/400/500/600/700 and AMD 300/400/500/600/700 chipsets. The flaw allows an attacker with the ability to trigger SMI 0xE3 to write arbitrary data to an arbitrary memory location, potentially leading to privilege escalation to SMM (ring -2).
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a Proof-of-Concept (PoC) exploit for CVE-2024-36877, targeting a vulnerability in the MSI ApService SMI handler on Windows systems. The exploit is implemented as a Windows kernel driver, with the main logic in 'exploit.cpp' and 'main.cpp'. The exploit works by: 1. Gaining access to physical memory via the '\Device\PhysicalMemory' device. 2. Locating the System Management Mode (SMM) core structures in physical memory by parsing the Windows registry at '\REGISTRY\MACHINE\HARDWARE\RESOURCEMAP\System Resources\Loader Reserved'. 3. Using EFI variables ('WMIAcpiMemAddr' and 'ApServiceAuthority') to communicate with the SMI handler and inject payloads. 4. Patching SMM code and copying custom shellcode (defined in 'shellcode.hpp') into SMM memory. 5. Triggering SMI interrupts to execute the injected shellcode, which can perform arbitrary actions in SMM, such as memory copying, module mapping, or command execution. The repository is structured as a Visual Studio kernel driver project, with source files for the exploit logic, physical memory access, SMM structure scanning, and shellcode payloads. The exploit is operational and demonstrates advanced techniques for firmware exploitation and SMM code execution. No network endpoints are present; all actions are performed locally with kernel and firmware-level access.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.