{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3abiostarbios_update_utility1.9.7.3/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:biostar:bios_update_utility:1.9.7.3:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-94146"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["BIOS Update Utility (1.9.7.3)"],"_cs_severities":["high"],"_cs_tags":["privilege-escalation","windows","driver-vulnerability"],"_cs_type":"advisory","_cs_vendors":["BioStar"],"content_html":"\u003cp\u003eA high-severity vulnerability (CVE-2026-94146) has been identified in the BioStar BIOS Update Utility version 1.9.7.3. The flaw exists within the BSMEM64_W10.sys driver, specifically in the IOCTL handler function sub_110BC. By manipulating the PhysicalAddress and Size arguments sent to the driver, a local attacker can trigger a write-what-where condition. This vulnerability enables a local user with standard privileges to escalate their permissions, potentially leading to full system compromise. Because the utility is intended to modify system firmware settings, the driver likely operates with elevated kernel-level privileges. Public exploit code for this vulnerability is currently available, and the vendor has not provided a patch or a response to the disclosure. Defenders should identify systems running this utility and consider removing it if not required for essential BIOS maintenance.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an attacker who already has local access to a system to elevate privileges, potentially gaining SYSTEM-level access. This poses a significant threat to internal security, as it allows attackers to bypass OS-level access controls, deploy persistence mechanisms, or extract sensitive data protected by kernel-level security features. The utility is primarily used on Windows 10 systems utilizing BioStar hardware.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification of endpoints running BioStar BIOS Update Utility version 1.9.7.3. Given the lack of a vendor patch and the existence of public exploit code, consider the following actions:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUninstall BioStar BIOS Update Utility 1.9.7.3 from all managed Windows 10 workstations.\u003c/li\u003e\n\u003cli\u003eMonitor for unauthorized loading of the BSMEM64_W10.sys driver or unusual IOCTL communication to this driver if it must remain installed for critical operations.\u003c/li\u003e\n\u003cli\u003eBlock the execution of known proof-of-concept tools targeting CVE-2026-94146 using Endpoint Detection and Response (EDR) blocklists.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-21T08:27:10Z","date_published":"2026-09-21T08:27:10Z","id":"https://feed.craftedsignal.io/briefs/2026-09-biostar-bios-vulnerability/","summary":"A write-what-where vulnerability in the BSMEM64_W10.sys driver of the BioStar BIOS Update Utility 1.9.7.3 allows local attackers to achieve privilege escalation.","title":"Local Privilege Escalation in BioStar BIOS Update Utility","url":"https://feed.craftedsignal.io/briefs/2026-09-biostar-bios-vulnerability/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:biostar:bios_update_utility:1.9.7.3:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}