IOCTL Vulnerability in BioStar BIOS Update Utility Affects Kernel Memory Access
CVE-2026-94146
9.3CRITICAL
What is CVE-2026-94146?
A write-what-where vulnerability has been identified in the BioStar BIOS Update Utility version 1.9.7.3, specifically affecting the IOCTL Handler function within the BSMEM64_W10.sys file. This flaw arises from improper handling of arguments associated with PhysicalAddress and Size, which may allow for unauthorized manipulation of memory locations. Exploitation requires local access to the system. Despite early notifications, the vendor has not addressed the issue or provided any response to mitigate the risks associated with this vulnerability. Potential attackers could leverage this flaw, creating an urgent need for users to apply security measures.
Affected Version(s)
BIOS Update Utility 1.9.7.3
