Skip to content
Threat Feed
high advisory

Local Privilege Escalation in BioStar Temperature Monitor Utility

CVE-2026-94142 is a local privilege escalation vulnerability in the BioStar Temperature Monitor Utility driver BS_HWMIO64_W10.sys, allowing a local attacker to execute arbitrary code with kernel privileges via a write-what-where vulnerability.

CVE search metadata

CVE search record: CVE-2026-94142. Severity: high. CVSS: 8.8. KEV: no. Product: Temperature Monitor Utility (1.2.1806.2200). Brief: Local Privilege Escalation in BioStar Temperature Monitor Utility. Brief link: https://feed.craftedsignal.io/briefs/2026-09-biostar-privilege-escalation/

CVE-2026-94142 is a security vulnerability residing in the BioStar Temperature Monitor Utility version 1.2.1806.2200. The vulnerability is located within the IOCTL handler of the BS_HWMIO64_W10.sys driver, specifically in the sub_1105C function. An attacker with local access to the system can exploit improper validation of the PhysicalAddress argument to perform a write-what-where operation. This manipulation allows for kernel memory corruption and potentially leads to the execution of arbitrary code with SYSTEM or kernel-level privileges. Public exploit code for this vulnerability has been disclosed, increasing the risk of exploitation by local attackers seeking to elevate privileges. BioStar did not respond to initial disclosure attempts, and no vendor patch is currently available.

Impact

Successful exploitation of this vulnerability allows a local user to escalate privileges to the kernel or SYSTEM level. This enables the attacker to bypass operating system security controls, install persistent backdoors, dump sensitive kernel memory, or disable endpoint protection software. The vulnerability affects environments where the BioStar Temperature Monitor Utility is installed on Windows systems.

Recommendation

Prioritize the identification and removal of vulnerable versions of the BioStar Temperature Monitor Utility (version 1.2.1806.2200) from all endpoints. Monitor system event logs for unusual driver loading activities or unexpected process executions occurring from user-space applications that interact with hardware monitoring interfaces. If the utility is not business-critical, implement a policy to block or uninstall the affected driver BS_HWMIO64_W10.sys.


Immediate actions

Audit endpoints for existence of BS_HWMIO64_W10.sys and version 1.2.1806.2200

IT Operations 48h

Mitigations

Remove or disable the BioStar Temperature Monitor Utility 1.2.1806.2200 from all production hosts

immediate IT Operations

CVE-2026-94142