CVE-2019-16098

HIGH7.8Published on September 11, 2019

The driver in Micro-Star MSI Afterburner 4.6.2.15658 (aka RTCore64.sys and RTCore32.sys) allows any authenticated user to read and write to arbitrary memory, I/O ports, and MSRs. This can be exploited for privilege escalation, code execution under high privileges, and information disclosure. These signed drivers can also be used to bypass the Microsoft driver-signing policy to deploy malicious code.

Early warning: exploitation observed

  • Exploitation observed since Oct 4, 2022
  • Not yet in the official CISA catalogue
  • First attack observed 1118 days after disclosure
  • Used in ransomware campaigns

Source: VulnCheck KEV · Apr 8, 2025 Aug 10, 2023 Jul 6, 2023 Feb 14, 2023 Nov 16, 2022 Nov 9, 2022

CVSS score7.8 / 10CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness type (CWE)CWE-125, CWE-787
Vendorsmsi

Affected products

VendorsProdottoVersioni
msiafterburner4.6.2.15658

Related articles

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE database