CVE-2026-94424

8.8

Moore Threads · MTT S80 Driver Package

A heap-based buffer overflow exists in the mtdispkm64.sys library of the Moore Threads MTT S80 driver, potentially allowing local code execution.

Executive summary

A heap-based buffer overflow vulnerability in the Moore Threads MTT S80 driver package poses a significant risk of local system compromise.

Vulnerability

This vulnerability occurs within the IOCTL Handler of the mtdispkm64.sys library, specifically in the sub_140001000 function. An attacker with local access can trigger a heap-based buffer overflow, which may lead to memory corruption or arbitrary code execution.

Business impact

The CVSS score of 8.8 indicates a high-severity flaw that could result in full system compromise, data loss, or unauthorized access to sensitive information stored on the host. While the attack requires local access, the nature of the driver-level flaw means that successful exploitation grants an attacker control over the underlying operating system, undermining all higher-level security controls.

Remediation

Immediate Action: Monitor the vendor website for security updates and apply them immediately once available.

Proactive Monitoring: Review system logs for unusual crashes or instability related to the mtdispkm64.sys driver.

Compensating Controls: Restrict local access to systems utilizing the affected hardware to authorized personnel only.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the severity of the vulnerability, administrators should prioritize identifying all systems running the affected MTT S80 driver. Since no patch is currently available, enforcing strict local access controls and monitoring for system anomalies is the most effective way to limit exposure until the vendor provides a remediation.

More Moore Threads CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Analyst report updated
  5. Published in the daily brief high section

Sources

Originally found and disclosed by Element2023H (VulDB User), with VulDB CNA Team (coordinator), per the CVE Program record.