CVE-2026-14961: CWE-284 Improper Access Control in Pegatron Corp. Tdelo64.sys
CVE-2026-14961 is a privilege escalation vulnerability in the Pegatron Corp. tdeio64.sys Windows kernel driver. The driver fails to properly validate IOCTL requests, allowing an unprivileged local attacker to perform arbitrary kernel memory reads and writes. Exploitation can lead to elevation of privileges to NT AUTHORITY\SYSTEM and full system compromise. No vendor-supported fix is currently available. Mitigations include disabling or removing the vulnerable driver where possible and using Windows security features like WDAC or HVCI to block vulnerable drivers.
AI Analysis
Technical Summary
The Pegatron tdeio64.sys driver exposes an unprotected IOCTL dispatch routine that does not validate the origin or permissions of user-supplied requests. This allows an unprivileged local attacker to send crafted DeviceIoControl requests to perform arbitrary kernel memory read and write operations. By overwriting the current process token with the SYSTEM token, the attacker can escalate privileges to NT AUTHORITY\SYSTEM. Additionally, the driver exposes IOCTLs that allow direct hardware I/O port interactions, potentially enabling manipulation of hardware resources beyond normal OS protections. Successful exploitation can lead to complete OS compromise, including bypassing security controls, credential theft from protected processes, rootkit installation, and kernel data structure manipulation. No official patch or fix is available at the time of publication.
Potential Impact
Exploitation grants arbitrary kernel memory read/write capabilities and SYSTEM-level privileges. This enables attackers to bypass or disable endpoint security, extract sensitive credentials, install persistent rootkits, and manipulate kernel and hardware resources, resulting in a full compromise of the affected Windows system.
Mitigation Recommendations
No vendor-supported fix is currently available. Organizations should disable or remove the vulnerable tdeio64.sys driver if it is not required. Prevent untrusted users from loading or interacting with the driver. Implement Windows Defender Application Control (WDAC) or Hypervisor-Protected Code Integrity (HVCI) where supported to block loading of known vulnerable drivers.
CVE-2026-14961: CWE-284 Improper Access Control in Pegatron Corp. Tdelo64.sys
Description
CVE-2026-14961 is a privilege escalation vulnerability in the Pegatron Corp. tdeio64.sys Windows kernel driver. The driver fails to properly validate IOCTL requests, allowing an unprivileged local attacker to perform arbitrary kernel memory reads and writes. Exploitation can lead to elevation of privileges to NT AUTHORITY\SYSTEM and full system compromise. No vendor-supported fix is currently available. Mitigations include disabling or removing the vulnerable driver where possible and using Windows security features like WDAC or HVCI to block vulnerable drivers.
CVSS v3.1
Score 6.2medium
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Pegatron tdeio64.sys driver exposes an unprotected IOCTL dispatch routine that does not validate the origin or permissions of user-supplied requests. This allows an unprivileged local attacker to send crafted DeviceIoControl requests to perform arbitrary kernel memory read and write operations. By overwriting the current process token with the SYSTEM token, the attacker can escalate privileges to NT AUTHORITY\SYSTEM. Additionally, the driver exposes IOCTLs that allow direct hardware I/O port interactions, potentially enabling manipulation of hardware resources beyond normal OS protections. Successful exploitation can lead to complete OS compromise, including bypassing security controls, credential theft from protected processes, rootkit installation, and kernel data structure manipulation. No official patch or fix is available at the time of publication.
Potential Impact
Exploitation grants arbitrary kernel memory read/write capabilities and SYSTEM-level privileges. This enables attackers to bypass or disable endpoint security, extract sensitive credentials, install persistent rootkits, and manipulate kernel and hardware resources, resulting in a full compromise of the affected Windows system.
Mitigation Recommendations
No vendor-supported fix is currently available. Organizations should disable or remove the vulnerable tdeio64.sys driver if it is not required. Prevent untrusted users from loading or interacting with the driver. Implement Windows Defender Application Control (WDAC) or Hypervisor-Protected Code Integrity (HVCI) where supported to block loading of known vulnerable drivers.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- certcc
- Date Reserved
- 2026-07-07T14:26:02.918Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://kb.cert.org/vuls/id/529388","vendor":"CERT"}]
Threat ID: 6a57c45368715ace431fb291
Added to database: 07/15/2026, 17:33:07 UTC
Last enriched: 08/04/2026, 13:01:41 UTC
Last updated: 08/28/2026, 10:52:06 UTC
Views: 69
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.