VYPR
Medium severity6.2NVD Advisory· Published Jul 15, 2026· Updated Jul 15, 2026

CVE-2026-14961

CVE-2026-14961

Description

Pegatron Tdelo64.sys exposes a privileged device interface, \\.\TdeIo, that fails to properly restrict access to sensitive IOCTL functionality. The driver's IOCTL dispatcher does not validate caller privileges or verify user-supplied kernel memory addresses before performing memory operations. By sending crafted requests to IOCTL, a local attacker can achieve arbitrary kernel memory read and write operations, leading to privilege escalation to NT AUTHORITY\SYSTEM, security product bypass, credential theft, or complete system compromise.

Affected products

1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.