← Back to search

CVE-2026-94146

8.8 HIGH

Published 2026-09-21 · Updated 2026-09-22

AI risk analysis

Summary
The flaw allows an attacker to manipulate the PhysicalAddress/Size argument, leading to a write-what-where condition, which can be exploited locally to gain unauthorized access or control.
Exploitability
Exploitation requires local access and manipulation of the PhysicalAddress/Size argument, making it moderately difficult.
Blast radius
If exploited, the vulnerability could result in unauthorized access or control of the system, potentially leading to data theft or system compromise.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to BioStar BIOS Update Utility 1.9.7.4 or later.
local-privilege-escalationwrite-what-wherebios-update

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

A vulnerability was found in BioStar BIOS Update Utility 1.9.7.3. This issue affects the function sub_110BC of the file BSMEM64_W10.sys of the component IOCTL Handler. The manipulation of the argument PhysicalAddress/Size results in write-what-where condition. Attacking locally is a requirement. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-119, CWE-123

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.