← Terug naar overzicht

A privilege escalation vulnerability exists in DirectIo64.sys, a kernel driver used by PassMark PerformanceTest (before 11.1 build 1012), BurnInTest (before 11.1 build 1000), and OSForensics (before 11.1 build 1016). The vulnerability arises from missing allowlist or port validation on exposed IOCTLs, allowing local users to issue arbitrary IN and OUT instructions to any x86 I/O port. Attackers can exploit this by obtaining a device handle and writing to sensitive hardware ports including PS/2 controller, CPU reset, CMOS configuration, and interrupt controller ports. This enables immediate system resets or other hardware-level manipulations from a standard user account. The flaw represents a significant local privilege escalation risk on Windows systems where any of the affected PassMark products are installed. Patches have been released in the respective updated build versions of each affected product.

Affected products

  • DirectIo64.sys
  • OSForensics before 11.1 build 1016
  • PassMark BurnInTest before 11.1 build 1000
  • PassMark PerformanceTest before 11.1 build 1012

Related CVE's

  • CVE-2026-80117

Categories

  • Identity & Access
  • Operating Systems
  • Zero-Day Vulnerabilities