Impact
A local user can send arbitrary IN and OUT instructions to any x86 I/O port by abusing unfiltered IOCTLs exposed by the DirectIo64.sys driver in PassMark PerformanceTest, BurnInTest, and OSForensics. The driver lacks an allowlist or port validation, allowing manipulation of sensitive ports such as the PS/2 controller, CPU reset ports, CMOS configuration ports, and the interrupt controller. An attacker could trigger an immediate system reset or otherwise alter hardware state, effectively escalating privileges from a standard user to a higher level of influence over system behavior.
Affected Systems
PassMark Software BurnInTest versions prior to 11.1 build 1000, PassMark Software OSForensics versions prior to 11.1 build 1016, and PassMark Software PerformanceTest versions prior to 11.1 build 1012 are affected. The vulnerability is located in the DirectIo64.sys device driver bundled with these products.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity; no EPSS data is available and the vulnerability is not listed in the CISA KEV catalog. The attack vector is local privilege escalation: any user with local access can acquire a handle to the driver and issue malicious IOCTLs. Successful exploitation could reset or otherwise manipulate hardware, jeopardizing system integrity and availability.
OpenCVE Enrichment