CVE-2026-94424
8.8Moore Threads · MTT S80 Driver Package
A heap-based buffer overflow exists in the mtdispkm64.sys library of the Moore Threads MTT S80 driver, potentially allowing local code execution.
Executive summary
A heap-based buffer overflow vulnerability in the Moore Threads MTT S80 driver package poses a significant risk of local system compromise.
Vulnerability
This vulnerability occurs within the IOCTL Handler of the mtdispkm64.sys library, specifically in the sub_140001000 function. An attacker with local access can trigger a heap-based buffer overflow, which may lead to memory corruption or arbitrary code execution.
Business impact
The CVSS score of 8.8 indicates a high-severity flaw that could result in full system compromise, data loss, or unauthorized access to sensitive information stored on the host. While the attack requires local access, the nature of the driver-level flaw means that successful exploitation grants an attacker control over the underlying operating system, undermining all higher-level security controls.
Remediation
Immediate Action: Monitor the vendor website for security updates and apply them immediately once available.
Proactive Monitoring: Review system logs for unusual crashes or instability related to the mtdispkm64.sys driver.
Compensating Controls: Restrict local access to systems utilizing the affected hardware to authorized personnel only.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the severity of the vulnerability, administrators should prioritize identifying all systems running the affected MTT S80 driver. Since no patch is currently available, enforcing strict local access controls and monitoring for system anomalies is the most effective way to limit exposure until the vendor provides a remediation.
More Moore Threads CVEs
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Analyst report updated
- Published in the daily brief high section
Sources
Originally found and disclosed by Element2023H (VulDB User), with VulDB CNA Team (coordinator), per the CVE Program record.
- VDB-408150 | Moore Threads MTT S80 Driver Package IOCTL mtdispkm64.sys sub_140001000 heap-based overflow Vulnerability database entry
- VDB-408150 | CTI Indicators (IOB, IOC, IOA)
- CVE-2026-94424 | CVE Analysis and Report Third-party advisory
- Submit #894806 | MOORE THREADS MTT S80 driver package v340.150 Buffer Overflow Third-party advisory