Description
A vulnerability was found in BioStar BIOS Update Utility 1.9.7.3. This issue affects the function sub_110BC of the file BSMEM64_W10.sys of the component IOCTL Handler. The manipulation of the argument PhysicalAddress/Size results in write-what-where condition. Attacking locally is a requirement. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-21
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Local write-what-where vulnerability leading to privilege escalation
Action: Assess Impact
AI Analysis

Impact

A write-what-where flaw exists in the sub_110BC function of BSMEM64_W10.sys within the BioStar BIOS Utility. The description states that local attack is required, so only an attacker with local physical or user access can exploit this. Manipulating the PhysicalAddress and Size arguments allows an attacker to overwrite arbitrary memory locations in the driver. This critical flaw can enable elevation of privileges or arbitrary code execution within the kernel, raising the impact to the highest severity. The vulnerability has a CVSS score of 9.3, indicating a complete compromise potential when exploited.

Affected Systems

The vulnerability affects BioStar BIOS Update Utility version 1.9.7.3. No other product variants or later versions are listed as affected. Users running this specific version should verify their installation and consider remediation.

Risk and Exploitability

Based on the description, the vulnerability requires local execution; an attacker must be able to execute code on the device or interact directly with the BIOS Update Utility. The public exploit has already been released, but no vendor response or patch is available yet, and the issue is not listed in CISA's Known Exploited Vulnerabilities catalog, though the high CVSS score signals a significant threat. Given the local nature, risk is highest for systems exposed to physical or near-physical attackers such as maintenance staff, end users with removable media, or compromised local accounts. The EPSS score is unavailable, but the known public exploit implies a tangible risk.

Generated by OpenCVE AI on September 21, 2026 at 08:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Remove or disable the vulnerable BIOS Update Utility until an official patch is released.
  • Apply any vendor‑issued update or firmware release that includes the write-what-where fix as soon as it becomes available.
  • Restrict local physical access to affected systems and enforce strict control over users who can run or modify firmware utilities.

Generated by OpenCVE AI on September 21, 2026 at 08:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in BioStar BIOS Update Utility 1.9.7.3. This issue affects the function sub_110BC of the file BSMEM64_W10.sys of the component IOCTL Handler. The manipulation of the argument PhysicalAddress/Size results in write-what-where condition. Attacking locally is a requirement. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title BioStar BIOS Update Utility IOCTL BSMEM64_W10.sys sub_110BC write-what-where
First Time appeared Biostar
Biostar bios Update Utility
Weaknesses CWE-119
CWE-123
CPEs cpe:2.3:o:biostar:bios_update_utility:*:*:*:*:*:*:*:*
Vendors & Products Biostar
Biostar bios Update Utility
References
Metrics cvssV2_0

{'score': 6.8, 'vector': 'AV:L/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


Subscriptions

Biostar Bios Update Utility
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-22T15:41:23.071Z

Reserved: 2026-09-20T20:31:10.779Z

Link: CVE-2026-94146

cve-icon Vulnrichment

Updated: 2026-09-22T14:56:11.877Z

cve-icon NVD

Status : Deferred

Published: 2026-09-21T07:16:53.993

Modified: 2026-09-22T16:18:17.603

Link: CVE-2026-94146

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T10:01:40Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-123

    Write-what-where Condition