CVE-2026-14960
9.8Pegatron · Tdelo64.sys
The Pegatron Tdelo64.sys driver exposes privileged hardware I/O interfaces, allowing unprivileged users to perform arbitrary port reads and writes, leading to potential system-wide compromise.
Executive summary
A critical vulnerability in the Pegatron Tdelo64.sys driver allows unauthenticated users to gain arbitrary hardware access, creating a high risk of system compromise and persistence.
Vulnerability
This vulnerability involves improper access control within the Tdelo64.sys driver, where the device interface fails to validate caller privileges for IOCTL handlers. Consequently, any unauthenticated user-mode process can interact with hardware registers directly.
Business impact
The ability for an unprivileged attacker to perform arbitrary I/O port operations poses a severe threat to system integrity and confidentiality. With a CVSS score of 9.8, this flaw facilitates unauthorized firmware manipulation, system instability, and the establishment of low-level persistence that is difficult to detect and remove.
Remediation
Immediate Action: Monitor vendor communications for an official driver update and apply it immediately upon release to address the improper access control.
Proactive Monitoring: Review system logs for unauthorized attempts to access or initialize the TdeIo device interface, particularly from non-privileged user accounts.
Compensating Controls: Restrict access to the underlying hardware interfaces at the operating system level if possible, or implement endpoint security policies that prevent unauthorized loading of vulnerable drivers.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the critical nature of this vulnerability and its potential for full system compromise, organizations should prioritize identifying systems running the affected version of Tdelo64.sys. Until a vendor patch is available, restrict access to the host environment to trusted users and monitor for any anomalous hardware interaction patterns.