IOCTL Vulnerability in BioStar BIOS Update Utility Affects Kernel Memory Access
CVE-2026-94146

9.3CRITICAL

Key Information:

Vendor

BiOStar

Vendor
CVE Published:
21 September 2026

What is CVE-2026-94146?

A write-what-where vulnerability has been identified in the BioStar BIOS Update Utility version 1.9.7.3, specifically affecting the IOCTL Handler function within the BSMEM64_W10.sys file. This flaw arises from improper handling of arguments associated with PhysicalAddress and Size, which may allow for unauthorized manipulation of memory locations. Exploitation requires local access to the system. Despite early notifications, the vendor has not addressed the issue or provided any response to mitigate the risks associated with this vulnerability. Potential attackers could leverage this flaw, creating an urgent need for users to apply security measures.

Affected Version(s)

BIOS Update Utility 1.9.7.3

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bigcat (VulDB User)
VulDB CNA Team
.