Unrated severityNVD Advisory· Published Jul 15, 2026· Updated Jul 15, 2026
CVE-2026-14961
CVE-2026-14961
Description
Pegatron Tdelo64.sys exposes a privileged device interface, \\.\TdeIo, that fails to properly restrict access to sensitive IOCTL functionality. The driver's IOCTL dispatcher does not validate caller privileges or verify user-supplied kernel memory addresses before performing memory operations. By sending crafted requests to IOCTL, a local attacker can achieve arbitrary kernel memory read and write operations, leading to privilege escalation to NT AUTHORITY\SYSTEM, security product bypass, credential theft, or complete system compromise.
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.