{"id":"CVE-2026-94424","published":"2026-09-21T21:17:21.793","lastModified":"2026-09-22T19:04:55.677","description":"A vulnerability has been found in Moore Threads MTT S80 Driver Package up to 340.150. Impacted is the function sub_140001000 in the library mtdispkm64.sys of the component IOCTL Handler. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The vendor was contacted early about this disclosure but did not respond in any way.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","cwes":["CWE-119","CWE-122"],"vendors":[],"products":[],"references":[{"url":"https://vuldb.com/cve/CVE-2026-94424","tags":[]},{"url":"https://vuldb.com/submit/894806","tags":[]},{"url":"https://vuldb.com/vuln/408150","tags":[]},{"url":"https://vuldb.com/vuln/408150/cti","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The vulnerability in Moore Threads MTT S80 Driver Package up to 340.150 allows for a heap-based buffer overflow, which can lead to remote code execution if exploited.","exploitability":"Exploitation requires local access and manipulation of the IOCTL Handler function, making it moderately difficult.","blast_radius":"If exploited, this vulnerability could result in unauthorized code execution on the affected system, leading to potential data loss or system compromise.","remediation":"Upgrade to version 340.151 or later of the Moore Threads MTT S80 Driver Package.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","local-privilege-escalation","driver-vulnerability"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-29T09:15:21.497Z"}}