PT-2026-86226 · Passmark · Osforensics+2
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PassMark PerformanceTest versions prior to 11.1 build 1012
BurnInTest versions prior to 11.1 build 1000
OSForensics versions prior to 11.1 build 1016
Description
A privilege escalation issue exists in the DirectIo64.sys driver. The flaw stems from missing validation of the physical address parameter within an exposed IOCTL handler. A local attacker can obtain a device handle and provide an arbitrary 64-bit physical address along with a bit index to trigger the
MmMapIoSpace function. This allows the attacker to clear arbitrary bits at any physical memory address, including kernel code pages or page table entries, which can lead to local privilege escalation or full system compromise.Recommendations
Update PassMark PerformanceTest to version 11.1 build 1012 or later.
Update BurnInTest to version 11.1 build 1000 or later.
Update OSForensics to version 11.1 build 1016 or later.
Exploit
Fix
LPE
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Burnintest
Osforensics
Performancetest