CVE-2026-14961

MEDIUM

Pegatron Corp. Tdelo64.sys - Privilege Escalation

Title source: rule
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-14961. PoCs published by FzRsLLaSheR.

AI-analyzed exploit summary Technical advisory detailing two privilege escalation vulnerabilities (CVE-2026-14960, CVE-2026-14961) in Pegatron's tdeio64.sys driver. The writeup explains improper access control and arbitrary kernel memory read/write primitives, enabling SYSTEM-level compromise and hardware I/O port manipulation, but does not include exploit code.

Description

Pegatron `Tdelo64.sys` exposes a privileged device interface, `\\.\TdeIo`, that fails to properly restrict access to sensitive IOCTL functionality. The driver's IOCTL dispatcher does not validate caller privileges or verify user-supplied kernel memory addresses before performing memory operations. By sending crafted requests to IOCTL, a local attacker can achieve arbitrary kernel memory read and write operations, leading to privilege escalation to `NT AUTHORITY\SYSTEM`, security product bypass, credential theft, or complete system compromise.

Exploits (1)

github WRITEUP
by FzRsLLaSheR · poc
https://github.com/FzRsLLaSheR/CVE-2026-14960-CVE-2026-14961

Technical advisory detailing two privilege escalation vulnerabilities (CVE-2026-14960, CVE-2026-14961) in Pegatron's tdeio64.sys driver. The writeup explains improper access control and arbitrary kernel memory read/write primitives, enabling SYSTEM-level compromise and hardware I/O port manipulation, but does not include exploit code.

Classification
Writeup 99%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Pegatron TdeIo Driver (tdeio64.sys)
Auth required
Prerequisites: Local access to a system with the vulnerable tdeio64.sys driver loaded · Low-privilege user context
mistral-large-3 · analyzed Jul 16, 2026 Full analysis →

References (1)

Core 1

Scores

CVSS v3 6.2
EPSS 0.0015
EPSS Percentile 4.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-20 CWE-269
Status published
Products (1)
Pegatron Corp./Tdelo64.sys 02-17-2025
Published Jul 15, 2026
Tracked Since Jul 15, 2026