CVE-2026-94129

LOWCVSS 8.5 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was detected in BioStar VALKYRIE AURORA 2.10.2411.0800. This vulnerability affects the function sub_1105C of the file BS_RVSIO64.sys of the component IOCTL Handler. The manipulation of the argument PhysicalAddress results in write-what-where condition. The attack needs to be approached locally. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-123

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-09-26: 309-26
Referenced assets2 URLs
Full discourse3 posts
  • Ryx@PadhiyarRushi

    BioStar "BS_RVSIO64.sys" IOCTL: local user writes any value to any physical address. CVE-2026-94129 (CVSS 9.3 v4), published Sept 21. "sub_1105C" in VALKYRIE AURORA 2.10.2411.0800 takes attacker "PhysicalAddress" and becomes write-what-where. Vendor did not respond. Exploit is public. Same week matching WWW bugs landed in "BS_LED64.sys" and "BSMEM64_W10.sys". https://github.com/lzty/CVE-2026-94129 #Cybersecurity #AI #AISecurity #MCP #Claude #GPT #Infosec #Trending #WindowsInternals #PrivilegeEscalation #LPE

    120104537
    925 followersView on X
  • ExploitGrid@exploitgrid

    🚨 CVE-2026-94129 | CVSS 9.3 Critical A vulnerability in BioStar VALKYRIE AURORA 2.10.2411.0800 allows a local attacker to manipulate a PhysicalAddress value and write an arbitrary value to an arbitrary memory address. And public exploit code is available.

    1102048
    66 followersView on X
  • ExploitGrid@exploitgrid

    Want the technical details in one place? Track CVE-2026-94129 on ExploitGrid — including its severity, affected software, exploit intelligence, and references. 🔗 https://exploitgrid.net/vulnerabilities/CVE-2026-94129 #CyberSecurity #CVE #InfoSec #WindowsSecurity #VulnerabilityManagement

    0000029
    66 followersView on X

Explore more