{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3abiostarvivid_led_dj4.0.2411.1500/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:biostar:vivid_led_dj:4.0.2411.1500:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-94128"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["VIVID LED DJ (4.0.2411.1500)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["BioStar"],"content_html":"\u003cp\u003eA critical security vulnerability has been identified in the BioStar VIVID LED DJ driver version 4.0.2411.1500. The flaw resides within the IOCTL handler function, specifically sub_1105C, located in the BS_LED64.sys kernel-mode driver. The vulnerability stems from improper handling of the AssociatedIrp argument, which permits an attacker with local access to the system to trigger a write-what-where condition. By crafting a specific IOCTL request, an unprivileged user can overwrite arbitrary kernel memory. This capability is a significant security concern as it can be leveraged to bypass Windows security controls, disable kernel-mode protections, or facilitate full system privilege escalation. Public exploit material exists for this vulnerability, and the vendor has not provided a response or a patch to address the issue. Defenders should prioritize monitoring for the loading of this specific driver or identifying local processes attempting unauthorized IOCTL communication with it.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-94128 requires local system access. If exploited, an attacker can transition from a low-privilege user context to SYSTEM-level privileges. This facilitates persistence, evasion of endpoint security solutions, and potential full system compromise. Given the nature of kernel-mode vulnerabilities, the impact is severe, potentially resulting in complete loss of system integrity and confidentiality.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor for the installation or presence of the BioStar VIVID LED DJ driver BS_LED64.sys on high-security or critical infrastructure assets.\u003c/li\u003e\n\u003cli\u003eImplement strict application control policies to prevent the execution of untrusted binaries that may attempt to interact with the vulnerable IOCTL handler.\u003c/li\u003e\n\u003cli\u003eAudit system configurations for the use of legacy or non-essential hardware drivers.\u003c/li\u003e\n\u003cli\u003eDue to the lack of a vendor patch, isolate systems running the vulnerable driver version (4.0.2411.1500) from untrusted user access if possible.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-21T02:25:43Z","date_published":"2026-09-21T02:25:43Z","id":"https://feed.craftedsignal.io/briefs/2026-09-biostar-driver-vulnerability/","summary":"A write-what-where vulnerability in the BS_LED64.sys driver of BioStar VIVID LED DJ 4.0.2411.1500 allows local users to achieve arbitrary memory writes and potential privilege escalation.","title":"Arbitrary Memory Write Vulnerability in BioStar VIVID LED DJ Driver","url":"https://feed.craftedsignal.io/briefs/2026-09-biostar-driver-vulnerability/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:biostar:vivid_led_dj:4.0.2411.1500:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}