VYPR
Unrated severityNVD Advisory· Published Jul 15, 2026· Updated Jul 15, 2026

CVE-2026-14961

CVE-2026-14961

Description

Pegatron Tdelo64.sys exposes a privileged device interface, \\.\TdeIo, that fails to properly restrict access to sensitive IOCTL functionality. The driver's IOCTL dispatcher does not validate caller privileges or verify user-supplied kernel memory addresses before performing memory operations. By sending crafted requests to IOCTL, a local attacker can achieve arbitrary kernel memory read and write operations, leading to privilege escalation to NT AUTHORITY\SYSTEM, security product bypass, credential theft, or complete system compromise.

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.