Skip to content
CVE Alert: CVE-2026-94129 – BioStar

CVE Alert: CVE-2026-94129 – BioStar

Redpacketsecurity •admin • September 21, 2026

A vulnerability was detected in BioStar VALKYRIE AURORA 2.10.2411.0800. This vulnerability affects the function sub_1105C of the file BS_RVSIO64.sys of the component IOCTL Handler. The manipulation of the argument PhysicalAddress results in write-what-where condition. The attack needs to be approached locally. The exploit is now public and may be used. The vendor was contacted early this disclosure but did not respond in any way.

**Risk verdict:** Treat as a high-priority remediation: exploitation is locally constrained, but public exploit availability and kernel-level impact materially increase the risk after an attacker gains a basic foothold.

**Why this matters:** Successful exploitation could enable arbitrary memory modification, leading to complete compromise of the host and disruption or manipulation of security-management operations. Realistic objectives include credential theft, persistence, disabling protective tooling, and using the affected workstation or server as a launch point into connected management infrastructure. KEV inclusion and active SSVC exploitation status are not provided, so confirmed in-the-wild use remains uncertain.

**Most likely attack path:** An attacker first obtains a low-privilege local account or code execution through phishing, exposed remote access, or another compromised application, then invokes the vulnerable driver interface without user interaction. Low attack complexity and changed scope mean successful exploitation may cross from the application host into higher-privilege system context and expose adjacent administrative assets.

**Who is most exposed:** Windows endpoints and servers running the access-control or security-management software, especially shared operator consoles, remotely administered systems, and hosts with broad network trust. Environments permitting standard users to log on to management systems face greater practical exposure.

Alert on unusual access to the associated kernel driver and IOCTL activity.

Hunt for unexpected privileged processes spawned by the management application.

Review recent local logons, remote-access sessions, and driver-load events.

Monitor security-tool tampering, memory-write anomalies, and lateral authentication.

Mitigation and prioritisation:

Apply the vendor’s security update or validated replacement on an expedited change.

Isolate management hosts and restrict inbound administration to dedicated jump servers.

Remove unnecessary local privileges and prevent untrusted users from interactive access.

If no fix exists, disable the vulnerable component only after testing operational impact, with rollback prepared.

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.

Extracted Entities

Attack Types (1)

MITRE ATT&CK (1)

Platforms (1)