PT-2026-102769 · Microsoft · Thread
CVE-2026-102757
·
Published
2026-09-29
·
Updated
2026-09-29
CVSS v4.0
8.5
High
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ThreadX (affected versions not specified)
Description
An unprivileged, memory-protected module can force the kernel to read and write memory at arbitrary addresses in privileged mode, allowing the module to clear the MPU (Memory Protection Unit) enable bit and remove its own isolation boundary. This occurs because the Module Manager only verifies if a requested object address falls outside the module. Since the manager's object pool is external to every module, an address shifted into the interior of one of the module's own privileged allocations can bypass this test. The module can then manipulate the bytes to mimic a control block ID, which the
txe layer accepts, ultimately enabling a privileged memset() function to be executed across a range chosen by the attacker.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Untrusted Pointer Dereference
Out of bounds Read
Memory Corruption
Type Confusion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Thread