rootpwn

critical · CVSS v3 8.8 · CVSS v4 9.3 · EPSS 0.00124

CVE-2026-94146

A vulnerability was found in BioStar BIOS Update Utility 1.9.7.3. This issue affects the function sub_110BC of the file …

Description

A vulnerability was found in BioStar BIOS Update Utility 1.9.7.3. This issue affects the function sub_110BC of the file BSMEM64_W10.sys of the component IOCTL Handler. The manipulation of the argument PhysicalAddress/Size results in write-what-where condition. Attacking locally is a requirement. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

Scores

Severity
critical
CVSS v2
6.8
CVSS v3
8.8
CVSS v4
9.3
EPSS
0.00124

← All CVEs