Impact
A local, unauthenticated attacker exploits a flaw in the DirectIo64.sys driver used by PassMark PerformanceTest, BurnInTest, and OSForensics. By supplying a caller‑controlled file path to an exposed IOCTL, the driver coerces the system to enumerate all physical memory ranges, map them into user space, and write a full RAM image to an attacker‑specified location. This bypasses user‑mode access control lists and captures sensitive data such as the LSASS working set, process memory, and cryptographic material from all running processes, resulting in a complete disclosure of confidential system contents.
Affected Systems
Affected products are PassMark Software’s BurnInTest versions before 11.1 build 1000, OSForensics versions before 11.1 build 1016, and PerformanceTest versions before 11.1 build 1012. Upgrading to any release at or beyond these build numbers removes the vulnerability.
Risk and Exploitability
The CVSS v3.1 score of 8.5 indicates high-severity information‑disclosure risk. EPSS information is unavailable, and the vulnerability is not listed in the CISA KEV catalogue. The attack vector is local and requires an unauthenticated user to execute a single IOCTL call. Once executed, the attacker obtains unrestricted read access to the entire physical memory in a SYSTEM context, making the vulnerability especially useful to credential theft, lateral movement, and other post‑compromise objectives.
OpenCVE Enrichment