CyberRota Analysis
AI-GeneratedThe vulnerability affects PassMark PerformanceTest, BurnInTest, and OSForensics prior to specified builds, allowing local users to exploit a weakness in DirectIo64.sys. This flaw enables privilege escalation through arbitrary I/O port access, potentially leading to system resets or hardware manipulation from standard user accounts. Organizations using these applications should prioritize patching to mitigate the risk of unauthorized system control and potential disruptions.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that allows local users to issue arbitrary IN and OUT instructions to any x86 I/O port due to missing allowlist or port validation on exposed IOCTLs. Attackers can obtain a device handle and write to sensitive ports including the PS/2 controller port, CPU reset ports, CMOS configuration ports, and interrupt controller ports to cause an immediate system reset or other hardware-level manipulation from a standard user account.