CyberRota Analysis
AI-GeneratedThe vulnerability affects PassMark PerformanceTest, BurnInTest, and OSForensics, allowing local users to exploit unvalidated IOCTLs in DirectIo64.sys for privilege escalation. This can lead to unauthorized modifications of hardware configurations, including arbitrary read/write operations on PCI devices, potentially enabling attackers to redirect DMA to malicious addresses or disrupt storage controller operations. Organizations using these products should prioritize patching to mitigate the risk of local privilege escalation and potential system compromise.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that allows local users to modify hardware configuration by exploiting exposed IOCTLs with no validation on device selection, register offset, or value. Attackers can obtain a device handle and issue arbitrary PCI configuration space read/write operations to enable Bus Master DMA on any PCI device, halt storage controller I/O by clearing command registers, or remap Base Address Registers to redirect DMA to an attacker-chosen physical address.