CVE-2026-30769 Details
Description
An issue in the TVicPort64.sys component of EnTech Taiwan TVicPort Product v4.0, File v5.2.1.0 allows attackers to escalate privileges via sending crafted IOCTL 0x80002008 requests.
A privilege escalation vulnerability has been identified in the TVicPort64.sys component of EnTech Taiwan's TVicPort Product version 4.0, File version 5.2.1.0. The issue arises because the driver creates its device object with a NULL Discretionary Access Control List (DACL), allowing any local user to open a handle and send crafted IOCTL 0x80002008 requests. This exploitation can lead to arbitrary physical memory read/write operations, enabling local privilege escalation and bypassing security features from any user context.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/lleekkoo/6c73fa4e137aca6f5dfe6aec4f6a7b29 | [email protected] | Third Party Advisory |
| https://www.entechtaiwan.com/dev/port/index.shtm | [email protected] | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | CISA-ADP |
| CWE-269 | Improper Privilege Management | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| entechtaiwan tvicport | 5.2.1.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 5, 2026 | Initial Analysis | [email protected] |
| Apr 29, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | New CVE Received | [email protected] |