Back Redpacketsecurity CVE Alert: CVE-2026-94142 – BioStar
A security vulnerability has been detected in BioStar Temperature Monitor Utility 1.2.1806.2200. Affected by this vulnerability is the function sub_1105C of the file BS_HWMIO64_W10.sys of the component IOCTL Handler. Such manipulation of the argument PhysicalAddress leads to write-what-where condition. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The vendor was contacted early this disclosure but did not respond in any way.
Treat this as a high-priority local privilege-escalation risk because a public exploit indicator exists, although KEV, SSVC exploitation state and EPSS data are not provided.
Successful exploitation could enable arbitrary kernel-level memory modification, allowing an attacker to take complete control of an endpoint, disable security tooling, steal credentials or deploy malware. The most realistic business impact is endpoint compromise followed by persistence and use of the device as a foothold for accessing higher-value systems.
### Most likely attack path
An attacker needs local access and limited privileges, but no user interaction; low attack complexity makes exploitation practical once the vulnerable driver is installed. The changed scope means compromise may extend beyond the utility itself, supporting privilege escalation and potential lateral movement using the host’s credentials, network access and trust relationships.
### Who is most exposed
Endpoints running the temperature-monitoring utility alongside its kernel driver are directly exposed, particularly shared workstations, engineering systems and operational environments where hardware-monitoring software is installed broadly. Asset inventory gaps may make unmanaged or specialist devices especially difficult to identify.
Alert on unexpected loading or installation of the associated kernel driver.
Monitor unusual device-object or IOCTL activity from non-standard processes.
Detect processes acquiring administrative or SYSTEM-level access shortly after utility activity.
Hunt for kernel crashes, security-tool tampering and new persistence mechanisms.
Review endpoint telemetry for suspicious local users interacting with the utility.
### Mitigation and prioritisation
Apply a vendor-supported fix or remove the utility and driver where not essential.
Until remediated, block driver installation, restrict local administrator rights and isolate affected endpoints where feasible.
Validate whether hardware-monitoring dependencies permit controlled removal before making changes.
Increase monitoring on systems that cannot be patched promptly; reassess when KEV, SSVC or EPSS data becomes available.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
