Impact
The vulnerability in DirectIo64.sys enables local users to modify hardware configuration via unvalidated IOCTL calls. By obtaining a device handle, an attacker can perform arbitrary PCI configuration space read and write operations, allowing the enabling of Bus Master DMA on any PCI device, the disabling of storage controller I/O, or the remapping of Base Address Registers to redirect DMA traffic to an attacker‑chosen address.
Affected Systems
Affected are PassMark Software products: BurnInTest (versions prior to 11.1 build 1000), OSForensics (versions prior to 11.1 build 1016) and PerformanceTest (versions prior to 11.1 build 1012).
Risk and Exploitability
The CVSS score is 8.5 indicating high severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. Attack requires local execution; any user who can run the affected applications may exploit the flaw. The lack of validation on device selection, register offset, and value means an attacker can impersonate privileged operations on hardware, compromising the integrity and availability of device configuration.
OpenCVE Enrichment