Executive brief
A security vulnerability exists in a Pegatron hardware driver used to manage low-level system components. An attacker who already has basic access to a computer can use this flaw to gain full administrative control (SYSTEM privileges). This allows them to bypass security software, steal sensitive credentials, and potentially install persistent malicious software that is difficult to detect.
Technical details
The Pegatron Tdelo64.sys driver (a Windows Driver Model driver) exposes the \\.\TdeIo device interface with an unprotected IOCTL dispatch routine. The dispatcher fails to validate caller privileges or verify user-supplied kernel memory addresses before performing memory operations. A local, unprivileged attacker can issue crafted DeviceIoControl requests to perform arbitrary kernel memory reads and writes. This can be leveraged to overwrite process tokens to achieve NT AUTHORITY\SYSTEM privileges, bypass security controls, or manipulate hardware I/O ports. As of July 2026, no vendor patch is available.
Affected products
- Pegatron Corp. Tdelo64.sys Up to 2025-02-17
Timeline
- 2026-06-10: other: Vendor notified
- 2026-07-15: advisory: CERT/CC and NVD advisories published