CVE-2026-94129
8.8BioStar · VALKYRIE AURORA
A memory corruption vulnerability in the BioStar VALKYRIE AURORA kernel driver allows local attackers to perform arbitrary memory writes via a crafted IOCTL request.
Executive summary
A critical write-what-where vulnerability in BioStar VALKYRIE AURORA enables local attackers to escalate privileges through kernel memory corruption.
Vulnerability
This vulnerability affects the BS_RVSIO64.sys kernel-mode driver, specifically the sub_1105C function within the IOCTL handler. A local attacker can manipulate the PhysicalAddress parameter to execute arbitrary memory writes, leading to privilege escalation.
Business impact
The CVSS score of 8.8 indicates a high-impact vulnerability that could compromise the entire operating system. An attacker could use this flaw to bypass kernel-mode security protections, leading to total system control and persistent unauthorized access to organizational assets.
Remediation
Immediate Action: Since no patch is currently available, organizations should restrict local user access to systems where VALKYRIE AURORA is installed.
Proactive Monitoring: Review system logs for unauthorized attempts to communicate with the BS_RVSIO64.sys kernel driver.
Compensating Controls: Utilize host-based intrusion prevention systems (HIPS) or EDR tools to block unauthorized IOCTL calls to sensitive kernel drivers.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists as referenced in the vulnerability disclosure.
Analyst recommendation
The presence of a public exploit for this kernel-level flaw necessitates immediate attention. Security teams must monitor for potential exploitation and restrict local access to the affected software until a vendor-provided patch is available.
More BioStar CVEs
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Analyst report updated
- Published in the daily brief high section
Sources
Originally found and disclosed by Bigcat (VulDB User), with VulDB CNA Team (coordinator), per the CVE Program record.
- VDB-408049 | BioStar VALKYRIE AURORA IOCTL BS_RVSIO64.sys sub_1105C write-what-where Vulnerability database entry
- VDB-408049 | CTI Indicators (IOB, IOC, IOA)
- CVE-2026-94129 | CVE Analysis and Report Third-party advisory
- Submit #893721 | BioStar VALKYRIE_AURORA_2.10.2411.0800 2.10.2411.0800 Arbitrary memory read and write Third-party advisory