CVE-2026-14961
Pegatron Tdelo64.sys exposes a privileged device interface, \\.\TdeIo, that fails to properly restrict access to sensitive IOCTL functionality. The driver's...
- Published
- Jul 15, 2026
- Updated
- Jul 15, 2026
- Assigning CNA
- certcc
- Evidence observed
- Aug 17, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NLow · next 30 days
- Percentile
- 5.8%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
Pegatron `Tdelo64.sys` exposes a privileged device interface, `\\.\TdeIo`, that fails to properly restrict access to sensitive IOCTL functionality. The driver's IOCTL dispatcher does not validate caller privileges or verify user-supplied kernel memory addresses before performing memory operations. By sending crafted requests to IOCTL, a local attacker can achieve arbitrary kernel memory read and write operations, leading to privilege escalation to `NT AUTHORITY\SYSTEM`, security product bypass, credential theft, or complete system compromise.
Sources
1- CVE-2026-14960-CVE-2026-14961Informational
Technical advisory detailing two privilege escalation vulnerabilities (CVE-2026-14960, CVE-2026-14961) in the Pegatron TdeIo64 driver, enabling arbitrary kernel memory read/write and unrestricted hardware I/O port access from unprivileged local users.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.