By vendor

Msi vulnerabilities

Known CVEs affecting Msi products, prioritized by severity, with SEC.co remediation and detection guidance.

2 published vulnerabilities

  • CVE-2026-37453HIGH 7.5

    MSI NBFoundation Service version 2.0.2506.1201 contains an insecure permissions vulnerability that allows an unauthenticated attacker on the network to read sensitive information. The vulnerability exists in a named pipe called MSI_SERVICE_2, which lacks proper access controls. An attacker with network access can connect to this pipe and extract data without needing credentials or user interaction.

  • CVE-2026-37454HIGH 7.5

    A vulnerability in MSI NBFoundation Service version 2.0.2506.1201 allows attackers on the network to access sensitive data through a weak encryption mechanism. The issue stems from improper permission controls that fail to prevent unauthorized access to information protected by 3DES-ECB encryption. An attacker requires no special privileges or user interaction to exploit this flaw, making it a direct threat to systems running the affected software.