在 BioStar Temperature Monitor Utility 1.2.1806.2200 中检测到一个安全漏洞。该漏洞影响了文件 BS_HWMIO64_W10.sys 中 IOCTL Handler 组件的函数 sub_1105C。通过操纵参数 PhysicalAddress,可触发“任意地址写入”(write-what-where)条件。该攻击需要以本地方式执行。漏洞利用技术已公开披露,并可能被利用。供应商已提前收到该漏洞披露通知,但未以任何方式作出回应。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| BioStar | Temperature Monitor Utility | 1.2.1806.2200 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| BioStar | Temperature Monitor Utility | 1.2.1806.2200 |
cpe:2.3:a:biostar:temperature_monitor_utility:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-94128 | 8.8 HIGH | BioStar VIVID LED DJ IOCTL BS_LED64.sys sub_1105C write-what-where |
| CVE-2026-94129 | 8.8 HIGH | BioStar VALKYRIE AURORA IOCTL BS_RVSIO64.sys sub_1105C write-what-where |
| CVE-2026-94146 | 8.8 HIGH | BioStar BIOS Update Utility IOCTL BSMEM64_W10.sys sub_110BC write-what-where |
No comments yet