CVE-2026-94146

8.8

BioStar · BIOS Update Utility

A memory corruption vulnerability in the BioStar BIOS Update Utility kernel driver allows local attackers to perform arbitrary memory writes via a crafted IOCTL request.

Executive summary

A critical write-what-where vulnerability in the BioStar BIOS Update Utility allows local attackers to escalate privileges by corrupting kernel memory.

Vulnerability

This vulnerability resides in the BSMEM64_W10.sys kernel-mode driver, specifically within the sub_110BC function of the IOCTL handler. A local authenticated attacker can manipulate PhysicalAddress and Size parameters to achieve a write-what-where condition, leading to potential system-wide compromise.

Business impact

The CVSS score of 8.8 reflects the high severity of this flaw, as it grants an attacker the ability to execute code with kernel-level privileges. A successful exploit could lead to full system compromise, unauthorized data access, and the bypass of security controls, posing a significant risk to organizational integrity and data confidentiality.

Remediation

Immediate Action: Since no patch is currently available, restrict access to the affected system to trusted, high-privileged users only.

Proactive Monitoring: Monitor system logs for unusual kernel-mode driver activity or attempts to interact with the BSMEM64_W10.sys driver.

Compensating Controls: Implement endpoint protection solutions capable of detecting kernel-level memory manipulation or unauthorized driver loading.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists as referenced in the vulnerability disclosure.

Analyst recommendation

Due to the severity of this kernel-level vulnerability and the lack of a vendor-provided patch, organizations should prioritize limiting local access to systems running this utility. Security teams must treat this as a high-priority risk and implement strict monitoring until a formal update is released by BioStar.

More BioStar CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Analyst report updated
  5. Published in the daily brief high section

Sources

Originally found and disclosed by Bigcat (VulDB User), with VulDB CNA Team (coordinator), per the CVE Program record.