Junglewise Threat Intelligence

CVE-2026-94129: BioStar VALKYRIE AURORA write-what-where in IOCTL handler

CVE-2026-94129 · Severity: high · CVSS 8.8 · Published 2026-09-21

Executive brief

BioStar VALKYRIE AURORA is a biometric access control system that manages physical security for buildings and facilities. A flaw in its driver allows a local attacker to write arbitrary data to arbitrary memory locations, leading to privilege escalation, system compromise, or denial of service. The vulnerability has public exploits available and the vendor has not responded to disclosure attempts.

Technical details

A write-what-where condition exists in the IOCTL handler of the BS_RVSIO64.sys driver (function sub_1105C), triggered by manipulation of the PhysicalAddress argument. The vulnerability requires local access to exploit and allows an attacker to write to arbitrary memory, potentially gaining kernel-level code execution. A patch status is unknown.

Affected products

  • BioStar VALKYRIE AURORA 2.10.2411.0800

Timeline

  • 2026-09-21: disclosed
  • other: Public exploit available; vendor non-responsive

References