CyberRota Analysis
AI-GeneratedThe BioStar BIOS Update Utility version 1.9.7.3 contains a high-severity vulnerability in its IOCTL Handler, specifically within the sub_110BC function of the BSMEM64_W10.sys file. This flaw allows for a write-what-where condition due to improper handling of the PhysicalAddress/Size argument, necessitating local access for exploitation. Organizations using this utility should prioritize patching or mitigating this vulnerability, especially given the public disclosure of the exploit.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A vulnerability was found in BioStar BIOS Update Utility 1.9.7.3. This issue affects the function sub_110BC of the file BSMEM64_W10.sys of the component IOCTL Handler. The manipulation of the argument PhysicalAddress/Size results in write-what-where condition. Attacking locally is a requirement. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.