← Back to search

CVE-2026-94146

8.8 HIGH

Published 2026-09-21 · Updated 2026-09-21

AI risk analysis

Summary
The flaw allows write-what-where conditions through manipulation of PhysicalAddress/Size arguments in BioStar BIOS Update Utility 1.9.7.3, enabling local attackers to exploit it.
Exploitability
Exploitation requires local access and knowledge of the vulnerability; public exploits exist but are not widely known.
Blast radius
If exploited, this could lead to full system compromise as local attackers can manipulate critical BIOS functions.
Prioritized remediation
Update to the latest version of BioStar BIOS Update Utility or apply vendor patches immediately.
local-privilege-escalationbiosutilitypatch-recommended

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

A vulnerability was found in BioStar BIOS Update Utility 1.9.7.3. This issue affects the function sub_110BC of the file BSMEM64_W10.sys of the component IOCTL Handler. The manipulation of the argument PhysicalAddress/Size results in write-what-where condition. Attacking locally is a requirement. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-119, CWE-123

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.