Executive brief
Moore Threads MTT S80 graphics driver contains a privilege escalation vulnerability in its IOCTL handler that allows local attackers to bypass privilege restrictions. An attacker with local system access can exploit this flaw to gain elevated privileges, potentially compromising system integrity and enabling further attacks.
Technical details
The vulnerability exists in the IOCTL handler component of mtdispkm64.sys library, specifically in the function sub_140006F0C, which improperly manages privileges. The attack vector is local and requires no authentication beyond having access to the system. A successful exploit grants the attacker elevated privileges on the affected machine.
Affected products
- Moore Threads MTT S80 Driver Package 340.150
Timeline
- 2026-09-21: disclosed