PT-2026-86228 · Passmark · Osforensics+2
CVSS v3.1
6.1
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
PassMark PerformanceTest versions prior to 11.1 build 1012
BurnInTest versions prior to 11.1 build 1000
OSForensics versions prior to 11.1 build 1016
Description
A privilege escalation and denial-of-service issue exists in the
DirectIo64.sys driver. Local attackers can exploit exposed IOCTLs (Input/Output Control codes) due to insufficient blocklist enforcement to read arbitrary Model-Specific Registers (MSRs) or write zero to any MSR. Model-Specific Registers are system registers used for toggling and monitoring specific processor features. By using the unrestricted write IOCTL, an attacker can zero out the system call handler MSR, leading to an immediate unrecoverable kernel crash upon the next system call, or read security-sensitive MSRs to locate kernel data structures.Recommendations
Update PassMark PerformanceTest to version 11.1 build 1012 or later.
Update BurnInTest to version 11.1 build 1000 or later.
Update OSForensics to version 11.1 build 1016 or later.
Exploit
Fix
LPE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Burnintest
Osforensics
Performancetest