boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Saturday, October 3, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-57851

Micro-Star International (MSI) KernCoreLib64.sys — MSI KernCoreLib64.sys Privilege Escalation via IOCTL Handlers
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   L   N   H   H   H    8.5   .0017    5.3     —
AFFECTED
  Product            Versions     Fixed
  KernCoreLib64.sys  unspecified  —
TIMELINE
  Jun 25  Reserved by VulnCheck
  Jul 7   Published (CNA: VulnCheck)
  Sep 24  EXPLOIT PUBLISHED — CVE-2026-57851 (Micro-Star International (MSI) KernCoreLib64.sys). Public exploit reference added.
CWE-782 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Deferred

Description

MSI Feature Manager contains a local privilege escalation vulnerability in the KernCoreLib64.sys kernel driver that allows any locally logged-on user to perform arbitrary physical memory read/write and unrestricted I/O port operations by accessing exposed IOCTL handlers without administrator privileges. Attackers can exploit the accessible device object through IOCTL handlers to manipulate kernel objects, tamper with kernel-mode callbacks, bypass Protected Process Light protections, and disable security software.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
June 25, 2026ReservedReserved by VulnCheck
July 7, 2026PublishedPublished (CNA: VulnCheck)
September 24, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2026-57851 (Micro-Star International (MSI) KernCoreLib64.sys). Public exploit reference added.

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
Micro-Star International (MSI)KernCoreLib64.sys———

Weaknesses

CWE-782

References (2)

Related

Authoritative record: CVE-2026-57851 at cve.org

Vendors: micro-star international (msi)

Weaknesses: CWE-782

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-57851 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Saturday, October 3, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.