rootpwn

critical · CVSS v3 8.8 · CVSS v4 9.3 · EPSS 0.00127

CVE-2026-94142

CVE-2026-94142 exposes a write-what-where flaw in the BioStar Temperature Monitor Utility driver (BS_HWMIO64_W10.sys). The vulnerability all

Overview

CVE-2026-94142 exposes a write-what-where flaw in the BioStar Temperature Monitor Utility driver (BS_HWMIO64_W10.sys). The vulnerability allows a local attacker to manipulate the PhysicalAddress argument of the IOCTL handler, potentially leading to arbitrary memory writes. It is rated critical and has been publicly disclosed.

Description

A security vulnerability has been detected in BioStar Temperature Monitor Utility 1.2.1806.2200. Affected by this vulnerability is the function sub_1105C of the file BS_HWMIO64_W10.sys of the component IOCTL Handler. Such manipulation of the argument PhysicalAddress leads to write-what-where condition. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Impact

The flaw can compromise confidentiality by leaking sensitive data, integrity by corrupting system memory, and availability by causing crashes or instability. Local users with sufficient privileges can exploit the driver to gain elevated rights or execute arbitrary code. System administrators and any services running under the affected driver are at risk.

Remediation

Apply the vendor’s official patch or upgrade to a newer version of the BioStar Temperature Monitor Utility. If a patch is unavailable, disable the driver or restrict local access to the IOCTL interface via group policy or ACLs. Enable Windows Driver Signature Enforcement and monitor for anomalous driver activity.

Risk context

Severity is critical with CVSS v3 score 8.8 and v4 score 9.3. The EPSS score of 0.00127 indicates a low probability of exploitation, but the high impact warrants prompt mitigation.

Affected products

  • BioStar Temperature Monitor Utility 1.2.1806.2200

Scores

Severity
critical
CVSS v2
6.8
CVSS v3
8.8
CVSS v4
9.3
EPSS
0.00127

write-what-where local-privilege-escalation driver critical BioStar IOCTL

← All CVEs