{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/biostar/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:biostar:valkyrie_aurora:2.10.2411.0800:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-94129"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["VALKYRIE AURORA (2.10.2411.0800)"],"_cs_severities":["high"],"_cs_tags":["windows","privilege-escalation","kernel"],"_cs_type":"advisory","_cs_vendors":["BioStar"],"content_html":"\u003cp\u003eCVE-2026-94129 describes a high-severity security vulnerability in the BioStar VALKYRIE AURORA software version 2.10.2411.0800. The flaw resides within the driver file BS_RVSIO64.sys, specifically impacting the IOCTL handler function sub_1105C. An attacker with local access to the system can manipulate the PhysicalAddress argument, resulting in a write-what-where vulnerability. This condition allows an adversary to perform arbitrary memory writes, potentially leading to local privilege escalation or system compromise. Publicly available exploit code exists for this vulnerability, and the vendor has not responded to disclosure attempts. Because the attack requires local access, this represents a significant risk for systems where untrusted users or applications may interact with the driver interface.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows a local user to execute arbitrary code with elevated privileges, potentially leading to a full system compromise. The vulnerability affects users of the BioStar VALKYRIE AURORA software version 2.10.2411.0800 on Windows operating systems. If exploited, an attacker could bypass OS security controls to install persistent backdoors, access sensitive data, or disable security software.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor system logs for unauthorized access to device drivers or attempts to interact with the BS_RVSIO64.sys interface.\u003c/li\u003e\n\u003cli\u003eAudit systems for the presence of BioStar VALKYRIE AURORA version 2.10.2411.0800 and consider restricting access to the executable or driver files until a vendor security update is available.\u003c/li\u003e\n\u003cli\u003eImplement endpoint security controls to restrict execution of untrusted binaries that might attempt to interact with IOCTLs of kernel-mode drivers.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-21T02:25:50Z","date_published":"2026-09-21T02:25:50Z","id":"https://feed.craftedsignal.io/briefs/2026-09-biostar-valkyrie-aurora-rce/","summary":"CVE-2026-94129 is a local privilege escalation vulnerability in the BioStar VALKYRIE AURORA driver BS_RVSIO64.sys allowing arbitrary memory writes via an IOCTL handler.","title":"Local Privilege Escalation in BioStar VALKYRIE AURORA Driver","url":"https://feed.craftedsignal.io/briefs/2026-09-biostar-valkyrie-aurora-rce/"},{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:biostar:vivid_led_dj:4.0.2411.1500:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-94128"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["VIVID LED DJ (4.0.2411.1500)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["BioStar"],"content_html":"\u003cp\u003eA critical security vulnerability has been identified in the BioStar VIVID LED DJ driver version 4.0.2411.1500. The flaw resides within the IOCTL handler function, specifically sub_1105C, located in the BS_LED64.sys kernel-mode driver. The vulnerability stems from improper handling of the AssociatedIrp argument, which permits an attacker with local access to the system to trigger a write-what-where condition. By crafting a specific IOCTL request, an unprivileged user can overwrite arbitrary kernel memory. This capability is a significant security concern as it can be leveraged to bypass Windows security controls, disable kernel-mode protections, or facilitate full system privilege escalation. Public exploit material exists for this vulnerability, and the vendor has not provided a response or a patch to address the issue. Defenders should prioritize monitoring for the loading of this specific driver or identifying local processes attempting unauthorized IOCTL communication with it.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-94128 requires local system access. If exploited, an attacker can transition from a low-privilege user context to SYSTEM-level privileges. This facilitates persistence, evasion of endpoint security solutions, and potential full system compromise. Given the nature of kernel-mode vulnerabilities, the impact is severe, potentially resulting in complete loss of system integrity and confidentiality.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor for the installation or presence of the BioStar VIVID LED DJ driver BS_LED64.sys on high-security or critical infrastructure assets.\u003c/li\u003e\n\u003cli\u003eImplement strict application control policies to prevent the execution of untrusted binaries that may attempt to interact with the vulnerable IOCTL handler.\u003c/li\u003e\n\u003cli\u003eAudit system configurations for the use of legacy or non-essential hardware drivers.\u003c/li\u003e\n\u003cli\u003eDue to the lack of a vendor patch, isolate systems running the vulnerable driver version (4.0.2411.1500) from untrusted user access if possible.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-21T02:25:43Z","date_published":"2026-09-21T02:25:43Z","id":"https://feed.craftedsignal.io/briefs/2026-09-biostar-driver-vulnerability/","summary":"A write-what-where vulnerability in the BS_LED64.sys driver of BioStar VIVID LED DJ 4.0.2411.1500 allows local users to achieve arbitrary memory writes and potential privilege escalation.","title":"Arbitrary Memory Write Vulnerability in BioStar VIVID LED DJ Driver","url":"https://feed.craftedsignal.io/briefs/2026-09-biostar-driver-vulnerability/"}],"language":"en","title":"CraftedSignal Threat Feed - BioStar","version":"https://jsonfeed.org/version/1.1"}