Impact
The flaw is an improper access control in the DirectIo64.sys kernel driver used by PassMark products. A local user can open a handle to the device object created without a security descriptor because the driver grants a permissive default Windows ACL. Once a handle is opened, the user can send IOCTL requests that invoke privileged hardware operations normally restricted to higher integrity levels, bypassing privilege checks. This allows local users to perform kernel‑level hardware manipulation, read or write system memory, or otherwise disrupt system integrity.
Affected Systems
PassMark Software BurnInTest versions earlier than 11.1 build 1000, PerformanceTest earlier than 11.1 build 1012, and OSForensics earlier than 11.1 build 1016 contain the vulnerable driver. All affected products expose the DirectIo64.sys driver on installation and are susceptible to the issue as described.
Risk and Exploitability
With a CVSS score of 8.5 the vulnerability is considered high severity. The EPSS score is not available and it is not listed in the CISA KEV catalog. Exploitation requires local, non‑privileged user access and is straightforward once the device handle is obtained. Consequently the risk of local privilege escalation is significant for any user with local access to the affected systems.
OpenCVE Enrichment