A privilege escalation vulnerability exists in DirectIo64.sys, a kernel driver used by PassMark PerformanceTest (before 11.1 build 1012), BurnInTest (before 11.1 build 1000), and OSForensics (before 11.1 build 1016). The driver exposes IOCTLs with no validation on device selection, register offset, or value, allowing local users to gain elevated privileges. Attackers can obtain a device handle and issue arbitrary PCI configuration space read/write operations. Exploitation can enable Bus Master DMA on any PCI device, halt storage controller I/O by clearing command registers, or remap Base Address Registers to redirect DMA to attacker-controlled physical memory. The vulnerability is rooted in insufficient input validation within the exposed kernel-level IOCTL interface. Patches are available in the respective updated builds of each affected product.