<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Temperature Monitor Utility (1.2.1806.2200) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/temperature-monitor-utility-1.2.1806.2200/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 21 Sep 2026 08:26:55 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/temperature-monitor-utility-1.2.1806.2200/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Local Privilege Escalation in BioStar Temperature Monitor Utility</title><link>https://feed.craftedsignal.io/briefs/2026-09-biostar-privilege-escalation/</link><pubDate>Mon, 21 Sep 2026 08:26:55 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-biostar-privilege-escalation/</guid><description>CVE-2026-94142 is a local privilege escalation vulnerability in the BioStar Temperature Monitor Utility driver BS_HWMIO64_W10.sys, allowing a local attacker to execute arbitrary code with kernel privileges via a write-what-where vulnerability.</description><content:encoded><![CDATA[<p>CVE-2026-94142 is a security vulnerability residing in the BioStar Temperature Monitor Utility version 1.2.1806.2200. The vulnerability is located within the IOCTL handler of the BS_HWMIO64_W10.sys driver, specifically in the sub_1105C function. An attacker with local access to the system can exploit improper validation of the PhysicalAddress argument to perform a write-what-where operation. This manipulation allows for kernel memory corruption and potentially leads to the execution of arbitrary code with SYSTEM or kernel-level privileges. Public exploit code for this vulnerability has been disclosed, increasing the risk of exploitation by local attackers seeking to elevate privileges. BioStar did not respond to initial disclosure attempts, and no vendor patch is currently available.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows a local user to escalate privileges to the kernel or SYSTEM level. This enables the attacker to bypass operating system security controls, install persistent backdoors, dump sensitive kernel memory, or disable endpoint protection software. The vulnerability affects environments where the BioStar Temperature Monitor Utility is installed on Windows systems.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the identification and removal of vulnerable versions of the BioStar Temperature Monitor Utility (version 1.2.1806.2200) from all endpoints. Monitor system event logs for unusual driver loading activities or unexpected process executions occurring from user-space applications that interact with hardware monitoring interfaces. If the utility is not business-critical, implement a policy to block or uninstall the affected driver BS_HWMIO64_W10.sys.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>