CVE-2026-94425
8.8Moore Threads · MTT S80 Driver Package
An improper privilege management vulnerability exists in the mtdispkm64.sys library of the Moore Threads MTT S80 driver, requiring local access to exploit.
Executive summary
A privilege management flaw in the Moore Threads MTT S80 driver package could allow a local attacker to elevate privileges or perform unauthorized operations.
Vulnerability
This flaw exists in the IOCTL Handler of the mtdispkm64.sys library, specifically within the sub_140006F0C function. The vulnerability enables improper privilege management, which can be exploited by an authenticated local user to perform actions beyond their intended permission level.
Business impact
With a CVSS score of 8.8, this vulnerability presents a high risk to organizational security. Successful exploitation could allow a standard user to gain elevated privileges, leading to unauthorized access to sensitive data, modification of system configurations, or persistence mechanisms that are difficult to detect.
Remediation
Immediate Action: Monitor the vendor support portal for official security patches and apply them as soon as they are released.
Proactive Monitoring: Audit user activity logs to identify any attempts to execute unauthorized administrative functions.
Compensating Controls: Implement the principle of least privilege by restricting user access to the hardware components and drivers on critical workstations.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The risk of privilege escalation makes this a priority for any system utilizing the affected hardware. Until the vendor releases a patch, security teams should focus on hardening the local environment and ensuring that only trusted users have the ability to interact with the system driver layer.
More Moore Threads CVEs
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Analyst report updated
- Published in the daily brief high section
Sources
Originally found and disclosed by Element2023H (VulDB User), with VulDB CNA Team (coordinator), per the CVE Program record.
- VDB-408151 | Moore Threads MTT S80 Driver Package IOCTL mtdispkm64.sys sub_140006F0C privileges management Vulnerability database entry
- VDB-408151 | CTI Indicators (IOB, IOC, TTP, IOA)
- CVE-2026-94425 | CVE Analysis and Report Third-party advisory
- Submit #894809 | MOORE THREADS MTT S80 driver package v340.150 Incorrect Use of Privileged APIs Third-party advisory