Executive brief
BioStar VIVID LED DJ is lighting control software that runs on Windows systems. A vulnerability in its kernel driver allows a local attacker to write arbitrary data to arbitrary memory locations, potentially leading to system compromise, data corruption, or privilege escalation. The flaw has been publicly disclosed and proof-of-concept code is available.
Technical details
A write-what-where vulnerability exists in the IOCTL handler (file BS_LED64.sys, function sub_1105C) due to improper validation of the AssociatedIrp argument. An attacker with local access can issue a specially crafted IOCTL request to write data to arbitrary kernel memory addresses. Exploitation requires local system access but no special privileges or user interaction.
Affected products
- BioStar VIVID LED DJ 4.0.2411.1500
Timeline
- 2026-09-21: disclosed
- 2026-09-21: advisory: Vendor did not respond to early disclosure notification