Skip to content
CVE Alert: CVE-2026-94128 – BioStar

CVE Alert: CVE-2026-94128 – BioStar

Redpacketsecurity admin September 21, 2026

A security vulnerability has been detected in BioStar VIVID LED DJ 4.0.2411.1500. This affects the function sub_1105C of the file BS_LED64.sys of the component IOCTL Handler. The manipulation of the argument AssociatedIrp leads to write-what-where condition. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used. The vendor was contacted early this disclosure but did not respond in any way.

This is a critical local privilege-escalation risk with publicly disclosed exploitation material, warranting urgent remediation on any exposed workstation or operator console.

Successful exploitation could provide arbitrary kernel-level memory modification, enabling complete compromise of confidentiality, integrity and availability. Realistic attacker objectives include disabling security tooling, stealing credentials, establishing persistence, or using the host as a launch point into wider operational environments. KEV, SSVC and EPSS values are not supplied, so the likelihood of active exploitation cannot be independently ranked beyond the public exploit disclosure.

### Most likely attack path

The path requires a local foothold and a low-privileged account: AV:L, AC:L, PR:L and UI:N indicate no user interaction and few technical barriers. The affected driver’s IOCTL interface could then be abused to alter privileged memory; changed Scope indicates potential impact beyond the initiating process and possible host-wide compromise. Remote exploitation is unlikely directly, but the weakness may become relevant after phishing, malware delivery, remote-access abuse or lateral movement.

### Who is most exposed

Prioritise Windows systems used to design, configure or operate LED displays, especially shared production workstations, event-control consoles and machines with broad network access. Environments where operators routinely have local accounts and third-party hardware drivers are installed face the greatest practical exposure.

Alert on unexpected loading or installation of the associated kernel driver and service.

Hunt for unusual device-handle access and IOCTL activity from non-standard processes.

Investigate sudden crashes, bugchecks, memory-integrity alerts or security-tool termination.

Correlate new local accounts, privilege changes and outbound connections after driver activity.

### Mitigation and prioritisation

Apply the vendor’s remediation or a fixed release as soon as available; do not rely on application-only updates.

Until patched, remove the driver where operationally safe, restrict local logons and isolate control workstations.

Use application control, driver-blocking policies and endpoint protection rules to prevent unapproved access.

Test display-control workflows in a maintenance window; retain rollback procedures because driver removal may disrupt operations.

Confirm KEV, SSVC and EPSS status and reassess priority when those data become available.

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.

Extracted Entities

Attack Types (2)

Platforms (1)