PT-2026-86230 · Passmark · Performancetest+2
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PassMark PerformanceTest versions prior to 11.1 build 1012
BurnInTest versions prior to 11.1 build 1000
OSForensics versions prior to 11.1 build 1016
Description
A privilege escalation issue exists in the
DirectIo64.sys driver. Local users can issue arbitrary IN and OUT instructions to any x86 I/O port because the exposed IOCTLs (Input/Output Control codes used by applications to communicate with device drivers) lack an allowlist or port validation. By obtaining a device handle, an attacker can write to sensitive ports, such as the PS/2 controller port, CPU reset ports, CMOS configuration ports, and interrupt controller ports, enabling hardware-level manipulation or an immediate system reset from a standard user account.Recommendations
Update PassMark PerformanceTest to version 11.1 build 1012 or later.
Update BurnInTest to version 11.1 build 1000 or later.
Update OSForensics to version 11.1 build 1016 or later.
Fix
LPE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Burnintest
Osforensics
Performancetest