Impact
A write-what-where flaw exists in the sub_110BC function of BSMEM64_W10.sys within the BioStar BIOS Utility. The description states that local attack is required, so only an attacker with local physical or user access can exploit this. Manipulating the PhysicalAddress and Size arguments allows an attacker to overwrite arbitrary memory locations in the driver. This critical flaw can enable elevation of privileges or arbitrary code execution within the kernel, raising the impact to the highest severity. The vulnerability has a CVSS score of 9.3, indicating a complete compromise potential when exploited.
Affected Systems
The vulnerability affects BioStar BIOS Update Utility version 1.9.7.3. No other product variants or later versions are listed as affected. Users running this specific version should verify their installation and consider remediation.
Risk and Exploitability
Based on the description, the vulnerability requires local execution; an attacker must be able to execute code on the device or interact directly with the BIOS Update Utility. The public exploit has already been released, but no vendor response or patch is available yet, and the issue is not listed in CISA's Known Exploited Vulnerabilities catalog, though the high CVSS score signals a significant threat. Given the local nature, risk is highest for systems exposed to physical or near-physical attackers such as maintenance staff, end users with removable media, or compromised local accounts. The EPSS score is unavailable, but the known public exploit implies a tangible risk.
OpenCVE Enrichment