
BioStar "BS_RVSIO64.sys" IOCTL: local user writes any value to any physical address. CVE-2026-94129 (CVSS 9.3 v4), published Sept 21. "sub_1105C" in VALKYRIE AURORA 2.10.2411.0800 takes attacker "PhysicalAddress" and becomes write-what-where. Vendor did not respond. Exploit is public. Same week matching WWW bugs landed in "BS_LED64.sys" and "BSMEM64_W10.sys". https://github.com/lzty/CVE-2026-94129 #Cybersecurity #AI #AISecurity #MCP #Claude #GPT #Infosec #Trending #WindowsInternals #PrivilegeEscalation #LPE

