Impact
PassMark’s DirectIo64.sys driver contains a hard‑coded 8‑byte key that allows a local attacker to calculate valid MD5 authentication tags, enabling arbitrary physical memory writes. By exploiting a secondary validation bypass through a driver‑issued bit‑clear IOCTL, the attacker can also disable MAC verification, size checks, and vendor ID checks for all subsequent write requests. This flaw permits the modification of kernel‑level memory, granting the attacker full control over the system and the ability to compromise confidentiality, integrity, and availability of the affected machine.
Affected Systems
The vulnerability affects PassMark Software’s BurnInTest before version 11.1 build 1000, PerformanceTest before 11.1 build 1012, and OSForensics before 11.1 build 1016. These products distribute DirectIo64.sys as a kernel driver.
Risk and Exploitability
With a CVSS score of 8.5 and no available EPSS data, the risk is high. The flaw is local in nature; an attacker must have physical machine access or local user privileges. However, the presence of a hard‑coded key and the ability to bypass validation gates make exploitation straightforward with existing tools, and the flaw is not listed in the CISA KEV catalog but still poses a serious threat to any system running the vulnerable driver.
OpenCVE Enrichment