Executive brief
A security vulnerability exists in a system driver used by older Toshiba and Dynabook laptops (released between 2009 and 2016) to manage BIOS passwords. A person with standard user access to the computer could exploit this flaw to gain unauthorized access to the system's physical memory. This could allow an attacker to bypass security protections or interfere with the operating system, though it requires the attacker to already have local access to the machine.
Technical details
The Generic IO & Memory Access driver, used for BIOS/Supervisor password configuration within Windows, fails to implement proper access controls on its IOCTL interface (CWE-782). This vulnerability allows a locally authenticated user without administrative privileges to perform arbitrary reads and writes to physical memory. The affected driver was pre-installed on various PC models released between 2009 and 2016. Because the driver is no longer supported, no patch is available; the recommended mitigation is to uninstall the driver and manage BIOS settings directly through the BIOS Setup Utility.
Affected products
- TOSHIBA CORPORATION Generic IO & Memory Access driver All versions
- Dynabook Inc. Generic IO & Memory Access driver All versions
Timeline
- 2026-06-19: advisory: Initial advisory published by Sharp/Dynabook
- 2026-06-25: disclosed: Public disclosure via JVN and NVD