CVE-2026-94146
8.8 HIGHPublished 2026-09-21 · Updated 2026-09-22
AI risk analysis
- Summary
- The flaw allows an attacker to manipulate the PhysicalAddress/Size argument, leading to a write-what-where condition, which can be exploited locally to gain unauthorized access or control.
- Exploitability
- Exploitation requires local access and manipulation of the PhysicalAddress/Size argument, making it moderately difficult.
- Blast radius
- If exploited, the vulnerability could result in unauthorized access or control of the system, potentially leading to data theft or system compromise.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to BioStar BIOS Update Utility 1.9.7.4 or later.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
A vulnerability was found in BioStar BIOS Update Utility 1.9.7.3. This issue affects the function sub_110BC of the file BSMEM64_W10.sys of the component IOCTL Handler. The manipulation of the argument PhysicalAddress/Size results in write-what-where condition. Attacking locally is a requirement. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Weaknesses
CWE-119, CWE-123
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-94128
- HIGHCVE-2026-94129
- HIGHCVE-2026-94142
- CRITICALCVE-2026-101354PoC
- HIGHCVE-2026-94424
- HIGHCVE-2026-17643
- HIGHCVE-2026-17644
- HIGHCVE-2026-17647
Related by shared AI tags and CWE weakness class. Browse the full archive.