Executive brief
The Moore Threads MTT S80 graphics driver contains a heap-based buffer overflow vulnerability in its IOCTL handler that can be exploited locally by an attacker with system access. An exploit could allow an attacker to execute arbitrary code, crash the system, or gain elevated privileges on affected machines. This driver is typically installed on systems using Moore Threads GPUs, potentially affecting graphics processing and system stability.
Technical details
A heap-based buffer overflow exists in the mtdispkm64.sys driver component within the IOCTL handler function sub_140001000, triggered by improper buffer size validation. The vulnerability requires local code execution capability and user-mode to kernel-mode transition via a malicious IOCTL call. Successful exploitation leads to kernel memory corruption and potential arbitrary code execution at kernel level.
Affected products
- Moore Threads MTT S80 Driver Package up to 340.150
Timeline
- 2026-09-21: disclosed