Exploitation Summary
EIP tracks 1 public exploit for CVE-2021-29337. PoCs published by rjt-gupta.
AI-analyzed exploit summary The repository contains a functional exploit PoC for CVE-2021-29337, demonstrating privilege escalation via arbitrary kernel memory manipulation through the vulnerable IOCTL 0x9C406104 in MSI Dragon Center's MODAPI.sys driver.
Description
MODAPI.sys in MSI Dragon Center 2.0.104.0 allows low-privileged users to access kernel memory and potentially escalate privileges via a crafted IOCTL 0x9c406104 call. This IOCTL provides the MmMapIoSpace feature for mapping physical memory.
Exploits (1)
The repository contains a functional exploit PoC for CVE-2021-29337, demonstrating privilege escalation via arbitrary kernel memory manipulation through the vulnerable IOCTL 0x9C406104 in MSI Dragon Center's MODAPI.sys driver.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H