CVE-2020-13149
Last modified
CVE-2020-13149 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Weak permissions on the "%PROGRAMDATA%\MSI\Dragon Center" folder in Dragon Center before 2.6.2003.2401, shipped with Micro-Star MSI Gaming laptops, allows local authenticated users to overwrite system files and gain escalated privileges. One attack method is to change the Recommended App binary within App.json. EPSS estimates a 0.45% chance of exploitation in the next 30 days.
Description
Weak permissions on the "%PROGRAMDATA%\MSI\Dragon Center" folder in Dragon Center before 2.6.2003.2401, shipped with Micro-Star MSI Gaming laptops, allows local authenticated users to overwrite system files and gain escalated privileges. One attack method is to change the Recommended App binary within App.json. Another attack method is to use this part of %PROGRAMDATA% for mounting an RPC Control directory.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Msi | Dragon Center | < 2.6.2003.2401 |
References
- https://github.com/rishaldwivedi/Public_Disclosure/blob/master/README.md#msi-dragon-center-eopExploit, Third Party Advisory
- https://github.com/rishaldwivedi/Public_Disclosure/blob/master/README.md#msi-dragon-center-eopExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-13149?
How severe is CVE-2020-13149?
How do I fix CVE-2020-13149?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-13136D-Link DSP-W215 1.26b03 devices send an obfuscated hash that…7.5
- CVE-2020-1314An elevation of privilege vulnerability exists in Windows Te…7.8
- CVE-2020-13143gadget_dev_desc_UDC_store in drivers/usb/gadget/configfs.c i…6.5
- CVE-2020-13144Studio in Open edX Ironwood 2.5, when CodeJail is not used, …8.8
- CVE-2020-13145Studio in Open edX Ironwood 2.5 allows users to upload SVG f…5.4
- CVE-2020-13146Studio in Open edX Ironwood 2.5 allows CSV injection because…8.8
- CVE-2020-1315An information disclosure vulnerability exists when Internet…5.3
- CVE-2020-13150D-link DSL-2750U ISL2750UEME3.V1E devices allow approximatel…7.8
- CVE-2020-13151Aerospike Community Edition 4.9.0.5 allows for unauthenticat…9.8
- CVE-2020-13152A remote user can create a specially crafted M3U file, media…5.5
- CVE-2020-13153app/View/Events/resolved_attributes.ctp in MISP before 2.4.1…6.1
- CVE-2020-13154Zoho ManageEngine Service Plus before 11.1 build 11112 allow…6.5
Are you affected by CVE-2020-13149?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
