CVE-2026-94142
8.8BioStar · Temperature Monitor Utility
A memory corruption vulnerability in the BioStar Temperature Monitor Utility kernel driver allows local attackers to perform arbitrary memory writes via a crafted IOCTL request.
Executive summary
A critical write-what-where vulnerability in the BioStar Temperature Monitor Utility allows local attackers to escalate privileges through malicious kernel memory manipulation.
Vulnerability
The flaw exists in the BS_HWMIO64_W10.sys kernel-mode driver, specifically within the sub_1105C function of the IOCTL handler. By manipulating the PhysicalAddress argument, a local attacker can trigger a write-what-where condition, enabling arbitrary memory modification.
Business impact
With a CVSS score of 8.8, this vulnerability represents a severe threat to system security. An attacker who gains local access can leverage this flaw to elevate their privileges to the kernel level, potentially disabling security agents or exfiltrating sensitive information from system memory.
Remediation
Immediate Action: In the absence of a patch, assess the necessity of this utility and consider uninstalling it from sensitive environments if it is not mission-critical.
Proactive Monitoring: Monitor system logs for suspicious IOCTL requests targeting the BS_HWMIO64_W10.sys driver.
Compensating Controls: Deploy endpoint security policies that enforce strict execution control and monitor for anomalous behavior originating from hardware monitoring utilities.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists as referenced in the vulnerability disclosure.
Analyst recommendation
Organizations should treat this vulnerability with high urgency given the availability of public exploit code. Until BioStar releases a security update, administrative teams should restrict local access to affected machines and evaluate the risk of maintaining this software in production environments.
More BioStar CVEs
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Analyst report updated
- Published in the daily brief high section
Sources
Originally found and disclosed by Bigcat (VulDB User), with VulDB CNA Team (coordinator), per the CVE Program record.
- VDB-408057 | BioStar Temperature Monitor Utility IOCTL BS_HWMIO64_W10.sys sub_1105C write-what-where Vulnerability database entry
- VDB-408057 | CTI Indicators (IOB, IOC, IOA)
- CVE-2026-94142 | CVE Analysis and Report Third-party advisory
- Submit #893919 | BioStar Temperature Monitor Utility 1.2.1806.2200 Arbitrary Kernel Memory Read/Write Third-party advisory