Skip to content
Critical Local Privilege Escalation Vulnerabilities in BioStar Software

Critical Local Privilege Escalation Vulnerabilities in BioStar Software

First seen 21 Sep 2026, 11:22 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 21, 2026 at 13:53 UTC
  • Three critical CVEs (CVE-2026-94128, CVE-2026-94142, CVE-2026-94129) identified in BioStar products.
  • All vulnerabilities allow local privilege escalation through IOCTL handler manipulation.
  • Publicly disclosed exploits increase risk of system compromise and credential theft.

Three critical vulnerabilities have been identified in BioStar software products, including BioStar VIVID LED DJ (CVE-2026-94128), BioStar Temperature Monitor Utility (CVE-2026-94142), and BioStar VALKYRIE AURORA (CVE-2026-94129). Each vulnerability allows for local privilege escalation through manipulation of IOCTL handlers, requiring local access to exploit. The exploits are publicly disclosed, posing significant risks of arbitrary kernel-level memory modification and potential system compromise. Affected systems include Windows workstations and servers running the respective BioStar software. The vendor has not responded to disclosure attempts, and no specific KEV, SSVC, or EPSS statuses have been provided, leaving the likelihood of active exploitation unassessed. Immediate remediation is advised, including patching and restricting local logons.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-21
CVE-2026-94128 published
A vulnerability in BioStar VIVID LED DJ allows local privilege escalation via IOCTL manipulation.
Redpacketsecurity
2026-09-21
CVE-2026-94142 published
A vulnerability in BioStar Temperature Monitor Utility enables local privilege escalation through IOCTL handler.
Redpacketsecurity
2026-09-21
CVE-2026-94129 published
A vulnerability in BioStar VALKYRIE AURORA allows local privilege escalation via IOCTL manipulation.
Redpacketsecurity

More articles in this cluster (6)

Following this threat?

Track BioStar and CVE-2026-94128 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed