Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 21 Sep 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in BioStar VIVID LED DJ 4.0.2411.1500. This affects the function sub_1105C of the file BS_LED64.sys of the component IOCTL Handler. The manipulation of the argument AssociatedIrp leads to write-what-where condition. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | BioStar VIVID LED DJ IOCTL BS_LED64.sys sub_1105C write-what-where | |
| First Time appeared |
Biostar
Biostar vivid Led Dj |
|
| Weaknesses | CWE-119 CWE-123 |
|
| CPEs | cpe:2.3:a:biostar:vivid_led_dj:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Biostar
Biostar vivid Led Dj |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-21T19:44:24.723Z
Reserved: 2026-09-20T17:44:53.397Z
Link: CVE-2026-94128
No data.
Status : Deferred
Published: 2026-09-21T02:16:54.037
Modified: 2026-09-21T13:33:33.387
Link: CVE-2026-94128
No data.
OpenCVE Enrichment
Updated: 2026-09-21T10:01:52Z