CVE-2019-16098
The driver in Micro-Star MSI Afterburner 4.6.2.15658 (aka RTCore64.sys and RTCore32.sys) allows any authenticated user to read and write to arbitrary memory, I/O ports, and MSRs. This can be exploited for privilege escalation, code execution under high privileges, and information disclosure. These signed drivers can also be used to bypass the Microsoft driver-signing policy to deploy malicious code.
Early warning: exploitation observed
- Exploitation observed since Oct 4, 2022
- Not yet in the official CISA catalogue
- First attack observed 1118 days after disclosure
- Used in ransomware campaigns
Source: VulnCheck KEV · Apr 8, 2025 Aug 10, 2023 Jul 6, 2023 Feb 14, 2023 Nov 16, 2022 Nov 9, 2022
CVSS score7.8 / 10
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HWeakness type (CWE)CWE-125, CWE-787
Vendorsmsi
Affected products
| Vendors | Prodotto | Versioni |
|---|---|---|
| msi | afterburner | 4.6.2.15658 |
Related articles
This product uses the NVD API but is not endorsed or certified by the NVD.
