Improper Privilege Management in Moore Threads MTT S80 Driver Package
CVE-2026-94425

9.3CRITICAL

Key Information:

Vendor
CVE Published:
21 September 2026

What is CVE-2026-94425?

A flaw has been identified in the Moore Threads MTT S80 Driver Package v340.150, specifically in the function sub_140006F0C within the mtdispkm64.sys library. This vulnerability arises from improper management of privileges within the IOCTL Handler component, allowing a local attacker to manipulate access rights. The exploitation of this vulnerability requires local access to the affected system. Despite early communication regarding this issue, the vendor has not addressed the matter.

Affected Version(s)

MTT S80 Driver Package 340.150

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Element2023H (VulDB User)
VulDB CNA Team
.