Executive brief
BioStar BIOS Update Utility is a system tool for updating BIOS firmware on computers. A flaw in its IOCTL handler allows a local attacker to write arbitrary data to system memory, potentially gaining elevated privileges or compromising system integrity. The vulnerability affects version 1.9.7.3 and exploit code has been publicly released.
Technical details
A write-what-where condition exists in the IOCTL handler (sub_110BC function) of the BSMEM64_W10.sys driver due to improper validation of PhysicalAddress and Size parameters. An authenticated local attacker can exploit this to write arbitrary data to kernel memory. A fix is not yet available from the vendor, who did not respond to early disclosure.
Affected products
- BioStar BIOS Update Utility 1.9.7.3
Timeline
- 2026-09-21: disclosed: Public exploit code released
- 2026-09-21: other: Vendor contacted early but did not respond