CVE-2026-94146: BioStar BIOS Update Utility IOCTL BSMEM64_W10.sys sub_110BC write-what-where
A vulnerability was found in BioStar BIOS Update Utility 1.9.7.3. This issue affects the function sub110BC of the file BSMEM64W10.sys of the component IOCTL Handler. The manipulation of the argument PhysicalAddress/Size results in write-what-where condition. Attacking locally is a requirement. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The attack must be performed locally, and the severity vector indicates that low privileges are required. No user interaction is required.
Is public exploit code available?
Yes. The vulnerability data states that an exploit has been made public and could be used.
Which installations are known to be affected?
BioStar BIOS Update Utility version 1.9.7.3 is identified as affected, specifically the BSMEM64_W10.sys IOCTL handler.
Is there a vendor response or confirmed remediation?
No vendor response is reported. The vendor was contacted early about the disclosure but did not respond, and the provided data does not identify a patch or workaround.