CVE-2026-94128 is a local write-what-where vulnerability in the IOCTL handler of the kernel driver distributed with BioStar VIVID LED DJ 4.0.2411.1500. The affected sub_1105C handler improperly processes the AssociatedIrp argument and exposes physical-memory mapping operations without restricting caller-supplied physical addresses to an allowlist. A caller able to access the driver device can induce writes to attacker-selected physical-memory locations. The issue is classified as CWE-123.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This is a small Rust local proof-of-concept repository claiming CVE-2026-94128. Its seven files consist of Cargo metadata/lockfile, an MIT license, a minimal README, and two Rust source files. src/main.rs is the executable entry point: it enables debug privilege, registers a BS_LED provider with the vdem helper library, starts/selects it, obtains the Windows kernel base, and demonstrates reading and modifying the kernel image header before attempting restoration. src/bsled.rs implements the provider around a BS_LED/BSLED64 driver, installs it as a service using an embedded driver blob referenced as crate::bin::BSLED64_SYS, opens the \\??\\BS_LED device, and invokes undocumented read/write IOCTLs 0x226040 and 0x226044. The read request contains a 32-bit physical address; the write request contains that address followed by attacker-controlled bytes. Provider cleanup stops, uninstalls, and deletes the driver service binary. No network targets or command-and-control functions are present. The supplied file listing does not include src/bin.rs despite main.rs declaring mod bin, so the actual embedded driver binary definition is unavailable for review; nevertheless, the visible code implements a credible arbitrary kernel-memory access demonstration rather than only vulnerability detection.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A locally exploitable write-what-where vulnerability in the BS_LED64.sys IOCTL handler shipped with BioStar VIVID LED DJ version 4.0.2411.1500. Manipulating the AssociatedIrp argument in sub_1105C can yield arbitrary kernel-memory write capability.
A locally exploitable write-what-where vulnerability in the IOCTL handler of BS_LED64.sys, shipped with BioStar VIVID LED DJ 4.0.2411.1500. Manipulation of the AssociatedIrp argument in sub_1105C causes the condition and could permit complete compromise of confidentiality, integrity, and availability after local authenticated access.
A Windows kernel-driver vulnerability in BIOSTAR VIVID LED DJ's BS_LED64.sys driver. The driver maps caller-supplied 32-bit physical addresses using MmMapIoSpace without an address allowlist, allowing physical-memory read/write operations that could compromise kernel memory and enable local privilege escalation.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.