CVE-2022-31877
HIGHMSI Center 1.0.41.0 - Privilege Escalation via Crafted TCP Packet
Title source: llmDescription
An issue in the component MSI.TerminalServer.exe of MSI Center v1.0.41.0 allows attackers to escalate privileges via a crafted TCP packet.
References (2)
Core 2
Core References
Vendor Advisory
http://msi.com
Exploit, Third Party Advisory
https://patsch.dev/2022/07/08/cve-2022-31877-privilege-escalation-in-msi-centers-msi-terminalserver-exe/
Scores
CVSS v3
8.8
EPSS
0.0044
EPSS Percentile
34.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-345
Status
published
Products (1)
msi/center
1.0.41.0
Published
Nov 28, 2022
Tracked Since
Feb 18, 2026