CVE-2026-94425 PUBLISHED

Moore Threads MTT S80 Driver Package IOCTL mtdispkm64.sys sub_140006F0C privileges management

Assigner: VulDB
Reserved: 21.09.2026 Published: 21.09.2026 Updated: 22.09.2026

A vulnerability was found in Moore Threads MTT S80 Driver Package 340.150. The affected element is the function sub_140006F0C in the library mtdispkm64.sys of the component IOCTL Handler. The manipulation results in improper privilege management. Attacking locally is a requirement. The vendor was contacted early about this disclosure but did not respond in any way.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X
CVSS Score: 9.3

Product Status

Vendor Moore Threads
Product MTT S80 Driver Package
Versions
  • Version 340.150 is affected

Credits

  • Element2023H (VulDB User) reporter
  • VulDB CNA Team coordinator

References

Problem Types

  • Improper Privilege Management CWE
  • Incorrect Privilege Assignment CWE