Junglewise Threat Intelligence

CVE-2026-94142: BioStar Temperature Monitor Utility write-what-where in IOCTL handler

CVE-2026-94142 · Severity: high · CVSS 8.8 · Published 2026-09-21

Executive brief

BioStar Temperature Monitor Utility is used for monitoring and managing hardware temperatures in systems. A write-what-where vulnerability in the IOCTL handler allows a local attacker to write arbitrary data to arbitrary memory locations, potentially leading to privilege escalation or system compromise.

Technical details

The vulnerability exists in the function sub_1105C of the BS_HWMIO64_W10.sys driver's IOCTL handler, where improper validation of the PhysicalAddress argument enables a write-what-where condition. A local attacker with basic privileges can exploit this to write arbitrary data to arbitrary memory addresses. The vulnerability has been publicly disclosed with exploit code available.

Affected products

  • BioStar Temperature Monitor Utility 1.2.1806.2200

Timeline

  • 2026-09-21: disclosed
  • other: Vendor contacted but did not respond

References