CVE-2026-30769

7.8

EnTech Taiwan · TVicPort

A privilege escalation vulnerability exists in the TVicPort64.sys driver, allowing local attackers to execute code with elevated privileges via crafted IOCTL requests.

Executive summary

A high-severity privilege escalation vulnerability in the EnTech Taiwan TVicPort driver allows local attackers to gain full system control.

Vulnerability

The vulnerability resides in the TVicPort64.sys component, which fails to properly validate input, allowing an authenticated local user to escalate privileges by sending a crafted IOCTL 0x80002008 request.

Business impact

The ability for a local attacker to escalate privileges to the system level poses a severe risk to organizational assets. Successful exploitation could lead to full system compromise, unauthorized data access, and the persistent installation of malicious software, severely undermining the security posture of the host environment. The CVSS score of 7.8 reflects the high potential for total system impact once local access is achieved.

Remediation

Immediate Action: Contact EnTech Taiwan or monitor their official website for a patched driver release and apply it as soon as it becomes available.

Proactive Monitoring: Review system logs for unusual IOCTL requests or suspicious process execution patterns originating from local user accounts.

Compensating Controls: Restrict local access to the affected machine to minimize the number of users capable of interacting with the vulnerable driver component.

Exploitation status

Public Exploit Available: Yes, a proof of concept exists via a GitHub Gist referenced in the vulnerability documentation.

Analyst recommendation

Given the potential for full privilege escalation, this vulnerability represents a significant security risk to any system running the vulnerable TVicPort driver. Administrators should prioritize identifying all instances of the affected software and restrict access until a formal patch can be deployed. Monitoring for unauthorized local activity remains essential until the underlying driver flaw is remediated.

Sources