PT-2026-86225 · Passmark · Osforensics+2
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PassMark PerformanceTest versions prior to 11.1 build 1012
BurnInTest versions prior to 11.1 build 1000
OSForensics versions prior to 11.1 build 1016
Description
An improper access control issue exists in the
DirectIo64.sys kernel driver. The driver creates a device object without a security descriptor, allowing unprivileged local users to open a handle to it. This enables attackers to issue IOCTLs (Input/Output Control codes used by applications to communicate with device drivers) through the permissive default Windows ACL (Access Control List) to perform privileged hardware operations, regardless of their privilege or integrity level.Recommendations
Update PassMark PerformanceTest to version 11.1 build 1012 or later.
Update BurnInTest to version 11.1 build 1000 or later.
Update OSForensics to version 11.1 build 1016 or later.
Exploit
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Burnintest
Osforensics
Performancetest