PT-2026-60231 · Pegatron · Tdelo64.Sys
CVE-2026-14960
·
Published
2026-07-15
·
Updated
2026-07-17
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Pegatron
Tdelo64.sys improperly exposes privileged hardware access functionality through the .TdeIo device interface. IOCTL handlers including TDE IOCTL INDEXIO READ and TDE IOCTL INDEXIO WRITE permit unprivileged user-mode callers to perform arbitrary hardware I/O port reads and writes without authorization checks. A local attacker can abuse this functionality to manipulate hardware registers, tamper with firmware-related interfaces, cause system instability, or establish persistent low-level compromise.Fix
Improper Privilege Management
Exposure of Resource to Wrong Sphere
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tdelo64.Sys