CVE-2026-94128

8.8

BioStar · VIVID LED DJ

BioStar VIVID LED DJ version 4.0.2411.1500 contains a write-what-where vulnerability in the BS_LED64.sys IOCTL handler, which may allow local attackers to gain elevated system privileges.

Executive summary

A high-severity memory corruption vulnerability exists in BioStar VIVID LED DJ that allows local attackers to achieve arbitrary code execution with system-level privileges.

Vulnerability

The vulnerability resides in the sub_1105C function of the BS_LED64.sys driver. By manipulating the AssociatedIrp argument within the IOCTL handler, a local attacker with low-level privileges can trigger a write-what-where condition, leading to potential system compromise.

Business impact

Successful exploitation of this vulnerability allows an attacker to gain full control over the host operating system. Given the CVSS score of 8.8, this represents a significant risk to data integrity, system availability, and the confidentiality of sensitive information stored on the affected workstation or server.

Remediation

Immediate Action: As there is currently no vendor-provided patch, users should restrict local access to the affected system and consider disabling the vulnerable BS_LED64.sys driver if it is not essential for business operations.

Proactive Monitoring: Monitor system logs for unauthorized attempts to load drivers or suspicious modifications to system memory and kernel-level processes.

Compensating Controls: Implement endpoint security solutions capable of detecting kernel-level exploitation patterns and enforce strict least-privilege access policies to prevent unauthorized local users from interacting with hardware drivers.

Exploitation status

Public Exploit Available: Yes — a public exploit has been disclosed via the VulDB reference.

Analyst recommendation

The severity of this vulnerability, combined with the lack of a vendor-provided fix, requires immediate defensive action. Administrators must limit local access to affected systems and monitor for any signs of privilege escalation attempts until the vendor releases a security update.

More BioStar CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources

Originally found and disclosed by Bigcat (VulDB User), with VulDB CNA Team (coordinator), per the CVE Program record.