Impact
Pegatron's Tdelo64.sys driver offers a \\\.\\TdeIo device interface that exposes privileged hardware I/O operations. The driver’s IOCTL handlers, such as TDE_IOCTL_INDEXIO_READ and TDE_IOCTL_INDEXIO_WRITE, allow any user‑mode application to read or write arbitrary hardware ports without performing authentication or authorization checks. An attacker exploiting this flaw can modify device registers, tamper with firmware interfaces, destabilize the system, or establish a persistent low‑level foothold that could be leveraged to gain higher privileges or conduct covert operations.
Affected Systems
Any system running Pegatron Corp.'s Tdelo64.sys driver is potentially vulnerable. Precise version details are not specified in the advisory, so the risk applies to all releases of the driver encountered in affected environments.
Risk and Exploitability
The CVSS score of 9.8 classifies this vulnerability as Critical. Although the EPSS score is reported as less than 1%, indicating limited evidence of active exploitation in the wild, the high severity and lack of an access control check mean that a local attacker with console or user privileges can exploit the flaw with relative ease. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog, but its implications for low‑level hardware control make it a high‑priority risk within the affected deployment.
OpenCVE Enrichment