← Terug naar overzicht

A critical improper access control vulnerability exists in the DirectIo64.sys kernel driver used by PassMark PerformanceTest, BurnInTest, and OSForensics. The flaw allows unprivileged local users to perform privileged hardware operations by opening a handle to a device object created without a security descriptor. Attackers can exploit permissive default Windows ACLs to issue IOCTLs and access restricted hardware operations regardless of their privilege or integrity level. Affected versions include PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016. The vulnerability represents a privilege escalation risk on Windows systems where these products are installed. Fixed versions have been released by PassMark for all three affected products.

Affected products

  • DirectIo64.sys kernel driver
  • OSForensics before 11.1 build 1016
  • PassMark BurnInTest before 11.1 build 1000
  • PassMark PerformanceTest before 11.1 build 1012

Related CVE's

  • CVE-2026-80112

Categories

  • Identity & Access
  • Operating Systems
  • Security Tools