PatchSiren cyber security CVE debrief
CVE-2026-94142 BioStar CVE debrief
A security vulnerability has been detected in BioStar Temperature Monitor Utility 1.2.1806.2200. The function sub_1105C of the file BS_HWMIO64_W10.sys of the component IOCTL Handler is affected, leading to a write-what-where condition. Local attack is required. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond.
- Vendor
- BioStar
- Product
- Temperature Monitor Utility
- CVSS
- HIGH 8.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-21
- Original CVE updated
- 2026-09-21
- Advisory published
- 2026-09-21
- Advisory updated
- 2026-09-21
Who should care
Local system administrators and defenders of systems running BioStar Temperature Monitor Utility 1.2.1806.2200 should be aware of this vulnerability. They should assess exposure, implement compensating controls, and monitor for potential exploitation attempts. IT security teams and vulnerability management teams are also relevant parties to address this issue.
Why it matters
CVE-2026-94142 is a high-severity vulnerability in BioStar Temperature Monitor Utility 1.2.1806.2200 that allows local attackers to exploit the IOCTL Handler, potentially leading to privilege escalation. Local system defenders should assess exposure and implement compensating controls.
- Local attackers may exploit this vulnerability to gain elevated privileges
- Successful exploitation requires local access to the system
- Defenders should verify if their systems are using the vulnerable IOCTL Handler
Technical summary
The vulnerability is in the sub_1105C function of BS_HWMIO64_W10.sys, leading to a write-what-where condition via IOCTL Handler manipulation. This allows local attackers to potentially escalate privileges. The affected product is BioStar Temperature Monitor Utility 1.2.1806.2200. Local attack is required for exploitation. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Technical details are limited to CVE and NVD information.
Defensive priority
High priority for local system defenders
Recommended defensive actions
- Review and assess exposure of local systems running BioStar Temperature Monitor Utility 1.2.1806.2200
- Verify if the system is using the vulnerable IOCTL Handler
- Implement compensating controls to limit local attack vectors
- Monitor for potential exploitation attempts
- Review system logs for suspicious activity
- Perform a thorough risk assessment for systems running the vulnerable utility
- Coordinate with vendors for potential patching or mitigation guidance
Evidence notes
The CVE record and NVD entry provide details on the vulnerability. However, the vendor did not respond to the disclosure. Local system defenders should verify if their systems are using the vulnerable IOCTL Handler and assess exposure. The exploit has been disclosed publicly and may be used. Evidence is limited to CVE and NVD details, with no additional source information available.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-94142 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-94142
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-94142 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-94142
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/cve/CVE-2026-94142
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/893919
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/408057
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/408057/cti
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.