CVE-2026-94142
Received Received - Intake

Write-What-Where Condition in BioStar Temperature Monitor Utility

Vulnerability report for CVE-2026-94142, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-21

Last updated on: 2026-09-21

Assigner: VulDB

Description

A security vulnerability has been detected in BioStar Temperature Monitor Utility 1.2.1806.2200. Affected by this vulnerability is the function sub_1105C of the file BS_HWMIO64_W10.sys of the component IOCTL Handler. Such manipulation of the argument PhysicalAddress leads to write-what-where condition. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-21
Last Modified
2026-09-21
Generated
2026-09-21
AI Q&A
2026-09-21
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
biostar temperature_monitor_utility 1.2.1806.2200

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-119 The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
CWE-123 Any condition where the attacker has the ability to write an arbitrary value to an arbitrary location, often as the result of a buffer overflow.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a write-what-where condition in BioStar Temperature Monitor Utility 1.2.1806.2200. It exists in the function sub_1105C of the file BS_HWMIO64_W10.sys within the IOCTL Handler component. An attacker can manipulate the PhysicalAddress argument to achieve arbitrary memory write operations.

Detection Guidance

This vulnerability is specific to the BioStar Temperature Monitor Utility 1.2.1806.2200 and involves a write-what-where condition in the BS_HWMIO64_W10.sys driver. Detection requires checking for the presence of this vulnerable driver and utility on the system.

Impact Analysis

This vulnerability allows local attackers to execute arbitrary code with high privileges on the affected system. It could lead to complete system compromise, data theft, or unauthorized system modifications. The public disclosure increases the risk of exploitation.

Mitigation Strategies

Immediately uninstall or disable the BioStar Temperature Monitor Utility 1.2.1806.2200. Check for and remove the vulnerable BS_HWMIO64_W10.sys driver. Ensure no unauthorized processes are using this driver. Monitor system logs for suspicious activity related to this driver.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-94142. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart