CVE-2026-57851 is a local privilege escalation vulnerability in MSI Feature Manager involving the KernCoreLib64.sys kernel driver. The driver exposes IOCTL handlers through an accessible device object without requiring administrator privileges, allowing a locally logged-on user to invoke functionality that should be restricted. Successful exploitation permits arbitrary physical memory read and write operations as well as unrestricted I/O port access from user-controlled context. Because the vulnerable functionality executes in kernel context, an attacker can use these primitives to directly manipulate kernel memory and system state, making the flaw suitable for elevation of privilege and security control bypass.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a Visual Studio C++ proof-of-concept for abusing a vulnerable Windows kernel driver identified in the README as KernCoreLib64.sys and exposed through the device name \\.\WinIo. The solution contains two standalone console projects: io_port and phys_mem. Both are local post-compromise tools rather than remote exploits. The io_port project is a capability demonstration for raw hardware access. It opens the driver device and uses DeviceIoControl with IOCTL_READ_IO_PORT (0x80102050) and IOCTL_WRITE_IO_PORT (0x80102054) to access PCI configuration ports 0xCF8 and 0xCFC. It writes a PCI config address value (0x80000000) and reads back vendor/device IDs for bus 0, device 0, function 0, then prints whether the chipset appears to be Intel or AMD. This demonstrates that the driver exposes unrestricted I/O port primitives. The phys_mem project is the actual privilege-escalation PoC. It opens the same driver and uses IOCTL_MAP_PHYS_MEM (0x80102040) to map physical memory starting at 0xFC000800. The code comments indicate the driver performs insufficient validation on the mapping size, allowing a very large mapping up to essentially all installed RAM. The program then walks the mapped physical memory in 8-byte increments looking for candidate EPROCESS structures using heuristics such as plausible PID values, valid CreateTime ranges, and other structure checks. It is tuned for Windows 11 25H2 with hardcoded EPROCESS/KPROCESS offsets. Once it identifies both the SYSTEM process and the current process, it reads their token fields and overwrites the current process token with the SYSTEM token, then verifies success by invoking whoami before and after the write. Repository structure is minimal: one solution file, two C++ source files, two Visual Studio project files plus filters for each project, and a short README with screenshots. There is no exploit framework, no networking, and no configurable payload delivery. The main purpose is to demonstrate vulnerable-driver abuse primitives leading to local privilege escalation through physical memory access and token stealing.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.