在 BioStar BIOS 更新工具 1.9.7.3 中发现一个安全漏洞。该漏洞影响组件 IOCTL 处理程序中 BSMEM64_W10.sys 文件的 sub_110BC 函数。通过操纵参数 PhysicalAddress/Size,可引发“写什么到哪里”(write-what-where)条件,即攻击者能够控制写入的数据内容及其目标地址。利用此漏洞需要本地访问权限。相关漏洞利用代码已公开,并可能被用于实际攻击。厂商虽已在此漏洞披露初期收到通知,但至今未作出任何回应。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| BioStar | BIOS Update Utility | 1.9.7.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| BioStar | BIOS Update Utility | 1.9.7.3 |
cpe:2.3:o:biostar:bios_update_utility:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-94128 | 8.8 HIGH | BioStar VIVID LED DJ IOCTL BS_LED64.sys sub_1105C write-what-where |
| CVE-2026-94129 | 8.8 HIGH | BioStar VALKYRIE AURORA IOCTL BS_RVSIO64.sys sub_1105C write-what-where |
| CVE-2026-94142 | 8.8 HIGH | BioStar Temperature Monitor Utility IOCTL BS_HWMIO64_W10.sys sub_1105C write-what-where |
No comments yet