A researcher discovered a vulnerability in MSI Center that allows local privilege escalation via a named pipe used by the Notebook Foundation service.
A researcher discovered a vulnerability in MSI Center that allows local privilege escalation via a named pipe used by the Notebook Foundation service.
MSI Center ships with MSI laptops and desktops, and the researcher examined the software after finding similar issues in AMD and ASUS OEM products.
The Notebook Foundation service creates a named pipe named \\.\pipe\MSI_SERVICE_2 with security settings that permit interaction from any authenticated user. Commands such as PC:REXE and PC:KEXE can be sent to execute code with LocalSystem privileges. A proof‑of‑concept script triggered cmd.exe, and remote code execution over SMB is possible when valid credentials are present.
The researcher emailed the vulnerability report to MSI PSIRT on May 10, 2026. MSI responded that a patch was developed and would be incorporated into MSI Center version 2.0.70.0 released June 1, 2026. The researcher requested a CVE identifier through VulDB, and the request remained under review as of July 1, 2026. The researcher also noted that no bug bounty payments have been issued for the reported issues.
The researcher continues to monitor the VulDB review process while awaiting distribution of the patch.
- Publisher
- Hacker News
- Reliability
- high
- Published
- 7/4/2026, 10:00:21 AM
- Retrieved
- 7/4/2026, 10:00:21 AM
- Relevance
- 80%
- Confidence
- 85%

