CVE-2026-94129 is a local write-what-where vulnerability in BioStar VALKYRIE AURORA 2.10.2411.0800. The flaw resides in an IOCTL handler within a kernel-mode driver. Insufficient validation of a caller-controlled physical-address argument permits an attacker to direct a write of attacker-influenced data to an attacker-selected memory location.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This is a standalone Windows Rust proof of concept claiming CVE-2026-94129. Its six Rust source files implement a generic vulnerable-driver provider interface, a BS_RVSIO64-specific provider, native registry-based kernel-driver service management, Windows privilege handling, and utility functions. The executable entry point is src/main.rs. The primary flow writes an embedded driver blob (referenced as crate::bin::BS_RVSIO64) to a randomized %TEMP% .sys file, creates a demand-start kernel-driver service under HKLM\SYSTEM\CurrentControlSet\Services, enables SeLoadDriverPrivilege, and loads it using NtLoadDriver. It then opens \\??\\BS_RVSIO and sends IOCTL 0x226040 and 0x226044 to read and write physical memory, respectively. The demonstration alters bytes at a fixed physical address and performs cleanup by unloading the driver, deleting the service registry tree, and removing the temporary driver. The source archive is incomplete as presented: main.rs declares mod bin and bsrvsio64.rs imports crate::bin::BS_RVSIO64, but src/bin.rs is absent from the supplied file list. Consequently, the shown repository will not compile unless that missing module and embedded driver data are restored. There are no network, web, command-and-control, or remote target interactions. The write demonstration is potentially system-destabilizing because it directly changes presumed kernel image memory.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A locally exploitable write-what-where vulnerability in the IOCTL handler of BS_RVSIO64.sys, affecting BioStar VALKYRIE AURORA version 2.10.2411.0800. An attacker can manipulate the PhysicalAddress argument passed to sub_1105C.
A local, low-complexity write-what-where vulnerability in the BS_RVSIO64.sys IOCTL handler shipped with BioStar VALKYRIE AURORA 2.10.2411.0800. Manipulating the PhysicalAddress argument to sub_1105C can permit arbitrary memory writes, with high impact to confidentiality, integrity, and availability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.