Impact
A buffer overflow and pointer corruption flaw in the sub_1105C function of the BS_RVSIO64.sys IOCTL handler allows an attacker with local access to write an arbitrary value to an arbitrary memory address, leading to a write‑what‑where condition that can be leveraged for arbitrary code execution.
Affected Systems
The vulnerability is present in BioStar VALKYRIE AURORA 2.10.2411.0800 and potentially in other firmware releases that include the same IOCTL handler.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity, while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Attackers must have local access to the device; the exploit code is publicly available, raising practical risk for environments where physical or local network access is not tightly controlled.
OpenCVE Enrichment