Impact
Pegatron's Tdelo64.sys driver exposes a privileged device interface (\\.\TdeIo) that fails to properly validate caller privileges or check user-supplied kernel memory addresses before executing IOCTL operations. By sending crafted IOCTL requests, a local attacker can perform arbitrary kernel memory reads and writes, ultimately gaining SYSTEM rights. This allows an attacker to bypass security products, steal credentials, or fully compromise the machine.
Affected Systems
The vulnerable component is the Pegatron Tdelo64.sys driver. No specific affected version information is provided in the data, so any installation of this driver may be at risk.
Risk and Exploitability
The CVSS score of 6.2 indicates a moderate severity vulnerability. The EPSS score of < 1% suggests a low probability of exploitation at the time of analysis, and it is not listed in CISA's KEV catalog. The likely attack vector is local via the uncontrolled IOCTL interface; an attacker must have physical or remote local access to the machine. While no public exploits have been reported, the ability to read/write kernel memory and elevate privileges poses a significant threat if exploited.
OpenCVE Enrichment