CVE-2026-94424 PUBLISHED

Moore Threads MTT S80 Driver Package IOCTL mtdispkm64.sys sub_140001000 heap-based overflow

Assigner: VulDB
Reserved: 21.09.2026 Published: 21.09.2026 Updated: 21.09.2026

A vulnerability has been found in Moore Threads MTT S80 Driver Package up to 340.150. Impacted is the function sub_140001000 in the library mtdispkm64.sys of the component IOCTL Handler. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The vendor was contacted early about this disclosure but did not respond in any way.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X
CVSS Score: 9.3

Product Status

Vendor Moore Threads
Product MTT S80 Driver Package
Versions
  • Version 340.150 is affected

Credits

  • Element2023H (VulDB User) reporter
  • VulDB CNA Team coordinator

References

Problem Types

  • Heap-based Buffer Overflow CWE
  • Memory Corruption CWE