<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>VALKYRIE AURORA (2.10.2411.0800) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/valkyrie-aurora-2.10.2411.0800/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 21 Sep 2026 02:25:50 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/valkyrie-aurora-2.10.2411.0800/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Local Privilege Escalation in BioStar VALKYRIE AURORA Driver</title><link>https://feed.craftedsignal.io/briefs/2026-09-biostar-valkyrie-aurora-rce/</link><pubDate>Mon, 21 Sep 2026 02:25:50 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-biostar-valkyrie-aurora-rce/</guid><description>CVE-2026-94129 is a local privilege escalation vulnerability in the BioStar VALKYRIE AURORA driver BS_RVSIO64.sys allowing arbitrary memory writes via an IOCTL handler.</description><content:encoded><![CDATA[<p>CVE-2026-94129 describes a high-severity security vulnerability in the BioStar VALKYRIE AURORA software version 2.10.2411.0800. The flaw resides within the driver file BS_RVSIO64.sys, specifically impacting the IOCTL handler function sub_1105C. An attacker with local access to the system can manipulate the PhysicalAddress argument, resulting in a write-what-where vulnerability. This condition allows an adversary to perform arbitrary memory writes, potentially leading to local privilege escalation or system compromise. Publicly available exploit code exists for this vulnerability, and the vendor has not responded to disclosure attempts. Because the attack requires local access, this represents a significant risk for systems where untrusted users or applications may interact with the driver interface.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows a local user to execute arbitrary code with elevated privileges, potentially leading to a full system compromise. The vulnerability affects users of the BioStar VALKYRIE AURORA software version 2.10.2411.0800 on Windows operating systems. If exploited, an attacker could bypass OS security controls to install persistent backdoors, access sensitive data, or disable security software.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Monitor system logs for unauthorized access to device drivers or attempts to interact with the BS_RVSIO64.sys interface.</li>
<li>Audit systems for the presence of BioStar VALKYRIE AURORA version 2.10.2411.0800 and consider restricting access to the executable or driver files until a vendor security update is available.</li>
<li>Implement endpoint security controls to restrict execution of untrusted binaries that might attempt to interact with IOCTLs of kernel-mode drivers.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>windows</category><category>privilege-escalation</category><category>kernel</category></item></channel></rss>