在 BioStar VIVID LED DJ 4.0.2411.1500 中检测到一个安全漏洞。该漏洞位于组件 IOCTL 处理程序中 BS_LED64.sys 文件的 sub_1105C 函数内。通过对参数 AssociatedIrp 的操纵,可导致“任意位置写入”(write-what-where)条件。利用此漏洞需要本地访问权限。该漏洞已被公开披露,可能会被用于攻击。厂商已提前获知此漏洞披露事宜,但未以任何方式作出回应。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| BioStar | VIVID LED DJ | 4.0.2411.1500 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| BioStar | VIVID LED DJ | 4.0.2411.1500 |
cpe:2.3:a:biostar:vivid_led_dj:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-94129 | 8.8 HIGH | BioStar VALKYRIE AURORA IOCTL BS_RVSIO64.sys sub_1105C write-what-where |
| CVE-2026-94142 | 8.8 HIGH | BioStar Temperature Monitor Utility IOCTL BS_HWMIO64_W10.sys sub_1105C write-what-where |
| CVE-2026-94146 | 8.8 HIGH | BioStar BIOS Update Utility IOCTL BSMEM64_W10.sys sub_110BC write-what-where |
No comments yet