Impact
The vulnerability arises in the sub_1105C function of the BS_LED64.sys IOCTL handler, where a manipulated AssociatedIrp argument can trigger a write-what-where condition. This exposes a classic buffer overflow (CWE‑119 and CWE‑123) that allows an attacker to overwrite arbitrary memory locations, potentially leading to arbitrary code execution and use of elevated privileges. The flaw does not rely on network access and requires only local physical or direct local access to the device.
Affected Systems
BioStar VIVID LED DJ devices running firmware version 4.0.2411.1500 are affected. The vulnerability is limited to this specific product line and version, and there is no indication that earlier or later releases are impacted.
Risk and Exploitability
The CVSS score of 9.3 marks this flaw as critical; the EPSS score is not available, so the current exploitation probability is unknown. The vulnerability is not yet listed in CISA’s KEV catalog. Attackers would need local access to the device to exploit the flaw, but once exploited, they could gain SYSTEM‑level privileges or even pivot to other systems if the device is networked. The combination of high severity, local attack vector, and potential for privilege escalation places significant risk on exposed deployments.
OpenCVE Enrichment