AMAZINGINDEX.COM 日报快照
50.7
VOL. 2026.07
2026.07.05
← 返回 2026.07.05 日报
日报快照 · Daily Snapshot
NO. 018

MSI Center 提权漏洞秒破 SYSTEM

#ARTICLE HackerNews 2026.07.05
推荐指数 42.0 NO. 018 · 2026.07.05
发布2026/07/04Score134Comments53

安全研究员在 MSI 预装软件中发现本地提权漏洞,攻击者可在数秒内获取 Windows SYSTEM 最高权限。该软件随 MSI 笔记本和整机出货,影响面极广,且漏洞利用门槛低。

OEM 预装软件一直是 Windows 生态的安全洼地,AMD、ASUS 刚被扒完轮到 MSI,说明这根本不是个案而是系统性问题。这些软件为了硬件监控需要高权限驱动,但代码质量远低于主流安全标准。

如果你是 AI 工程师用 Windows 工作站跑训练或推理,建议立刻检查是否装了 MSI Center/Armoury Crate/OMEN Gaming Hub 这类 OEM 工具,能卸载就卸载,不能卸载的至少关闭后台服务。企业 IT 需要把 OEM 软件纳入漏洞管理流程,不能因为是出厂自带就忽略。

意见分歧 49 条评论

核心争论:OEM预装软件质量低下且漏洞频发,社区更倾向反向工程替代而非信任厂商修复

huflungdung

You have physical access to the machine. Dump its bios and inject this https://download.microsoft.com/download/8/a/2/8a2fb72d-9b96-... Shrug.emoji

Klathmon

Is there any valid reason to still be using 3DES in 2026? It was formally deprecated in 2018 and has been surpassed in just about every single way by AES long before that. At this point I feel like it's use is such a huge red flag

Pxtl

I mean they're still using Inno Setup which was pretty cool in 2004.

替代方案: MSIMSIXWiXNSISInno SetupOpenRGB
查看原文 →