Impact
The flaw is a write‑what‑where bug in the IOCTL handler of BS_HWMIO64_W10.sys, allowing a local user to write to an arbitrary physical address via the PhysicalAddress argument. This can lead to privilege escalation or arbitrary code execution on the compromised system, affecting confidentiality, integrity, and availability.
Affected Systems
BioStar Temperature Monitor Utility version 1.2.1806.2200 on Windows systems contains the vulnerable sub_1105C function. Only systems running this exact build are impacted; newer releases or other vendors are not listed as affected.
Risk and Exploitability
With a CVSS score of 9.3, this vulnerability is deemed critical. The EPSS score is not available, and the vulnerability is not present in the CISA KEV catalog. The known exploit requires local execution, which means that an attacker with local access can abuse the flaw, and the public disclosure indicates that it can be leveraged. The lack of a vendor response suggests that the risk remains unresolved until a patch is released.
OpenCVE Enrichment