Junglewise Threat Intelligence

CVE-2026-94128: BioStar VIVID LED DJ write-what-where in IOCTL handler

CVE-2026-94128 · Severity: high · CVSS 8.8 · Published 2026-09-21

Executive brief

BioStar VIVID LED DJ is lighting control software that runs on Windows systems. A vulnerability in its kernel driver allows a local attacker to write arbitrary data to arbitrary memory locations, potentially leading to system compromise, data corruption, or privilege escalation. The flaw has been publicly disclosed and proof-of-concept code is available.

Technical details

A write-what-where vulnerability exists in the IOCTL handler (file BS_LED64.sys, function sub_1105C) due to improper validation of the AssociatedIrp argument. An attacker with local access can issue a specially crafted IOCTL request to write data to arbitrary kernel memory addresses. Exploitation requires local system access but no special privileges or user interaction.

Affected products

  • BioStar VIVID LED DJ 4.0.2411.1500

Timeline

  • 2026-09-21: disclosed
  • 2026-09-21: advisory: Vendor did not respond to early disclosure notification

References