๐Ÿ” CVE Alert

CVE-2026-94146

HIGH 8.8

BioStar BIOS Update Utility IOCTL BSMEM64_W10.sys sub_110BC write-what-where

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was found in BioStar BIOS Update Utility 1.9.7.3. This issue affects the function sub_110BC of the file BSMEM64_W10.sys of the component IOCTL Handler. The manipulation of the argument PhysicalAddress/Size results in write-what-where condition. Attacking locally is a requirement. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

CWE CWE-123 CWE-119
Vendor biostar
Product bios update utility
Published Sep 21, 2026
Stay Ahead of the Next One

Get instant alerts for biostar bios update utility

Be the first to know when new high vulnerabilities affecting biostar bios update utility are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

BioStar / BIOS Update Utility
1.9.7.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/408061 vuldb.com: https://vuldb.com/vuln/408061/cti vuldb.com: https://vuldb.com/cve/CVE-2026-94146 vuldb.com: https://vuldb.com/submit/894066

Credits

๐Ÿ” Bigcat (VulDB User) VulDB CNA Team