PT-2026-102769 · Microsoft · Thread

CVE-2026-102757

·

Published

2026-09-29

·

Updated

2026-09-29

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ThreadX (affected versions not specified)
Description An unprivileged, memory-protected module can force the kernel to read and write memory at arbitrary addresses in privileged mode, allowing the module to clear the MPU (Memory Protection Unit) enable bit and remove its own isolation boundary. This occurs because the Module Manager only verifies if a requested object address falls outside the module. Since the manager's object pool is external to every module, an address shifted into the interior of one of the module's own privileged allocations can bypass this test. The module can then manipulate the bytes to mimic a control block ID, which the txe layer accepts, ultimately enabling a privileged memset() function to be executed across a range chosen by the attacker.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Untrusted Pointer Dereference

Out of bounds Read

Memory Corruption

Type Confusion

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-102757
GHSA-RRJJ-JWCW-HVF8

Affected Products

Thread