Junglewise Threat Intelligence

CVE-2026-94425: Moore Threads MTT S80 Driver privilege escalation in IOCTL handler

CVE-2026-94425 · Severity: high · CVSS 8.8 · Published 2026-09-21

Executive brief

Moore Threads MTT S80 graphics driver contains a privilege escalation vulnerability in its IOCTL handler that allows local attackers to bypass privilege restrictions. An attacker with local system access can exploit this flaw to gain elevated privileges, potentially compromising system integrity and enabling further attacks.

Technical details

The vulnerability exists in the IOCTL handler component of mtdispkm64.sys library, specifically in the function sub_140006F0C, which improperly manages privileges. The attack vector is local and requires no authentication beyond having access to the system. A successful exploit grants the attacker elevated privileges on the affected machine.

Affected products

  • Moore Threads MTT S80 Driver Package 340.150

Timeline

  • 2026-09-21: disclosed

References

Related threats