---
id: CVE-2026-94146
title: A vulnerability was found in BioStar BIOS Update Utility 1.9.7.3
summary: >-
  A vulnerability was found in BioStar BIOS Update Utility 1.9.7.3. This issue
  affects the function sub_110BC of the file BSMEM64_W10.sys of the component
  IOCTL Handler. The manipulation of the argument PhysicalAddress/Size results
  in writ…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-119
  - CWE-123
vendor: BioStar
product: BIOS Update Utility
affected:
  - bios_update_utility 1.9.7.3
published: '2026-09-21'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T13:33:33.387'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-94146'
references:
  - url: 'https://vuldb.com/cve/CVE-2026-94146'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/894066'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/408061'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/408061/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
epss: 0.00124
epssPercentile: 0.0248
ingestedAt: '2026-09-21T07:33:19.003Z'
---

## Overview

A vulnerability was found in BioStar BIOS Update Utility 1.9.7.3. This issue affects the function sub_110BC of the file BSMEM64_W10.sys of the component IOCTL Handler. The manipulation of the argument PhysicalAddress/Size results in write-what-where condition. Attacking locally is a requirement. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
