{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/osforensics--11.1-build-1016/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:passmark:performancetest:*:*:*:*:*:*:*:*","cpe:2.3:a:passmark:burnintest:*:*:*:*:*:*:*:*","cpe:2.3:a:passmark:osforensics:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-80113"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["PerformanceTest (\u003c 11.1 build 1012)","BurnInTest (\u003c 11.1 build 1000)","OSForensics (\u003c 11.1 build 1016)"],"_cs_severities":["high"],"_cs_tags":["privilege-escalation","windows","kernel-vulnerability"],"_cs_type":"advisory","_cs_vendors":["PassMark Software"],"content_html":"\u003cp\u003ePassMark Software has disclosed a privilege escalation vulnerability affecting PerformanceTest (before 11.1 build 1012), BurnInTest (before 11.1 build 1000), and OSForensics (before 11.1 build 1016). The flaw resides in the DirectIo64.sys driver, which exposes an IOCTL handler that fails to validate the physical address parameter. A local attacker can gain a device handle to the driver and invoke MmMapIoSpace with a user-supplied 64-bit physical address and bit index. By clearing bits in critical kernel code pages or page table entries, an attacker can modify kernel-level structures to achieve local privilege escalation. This vulnerability represents a significant risk for systems where these forensic and testing tools are installed, as they often run with high privileges.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains low-privileged local access to a Windows system where affected PassMark software is installed.\u003c/li\u003e\n\u003cli\u003eAttacker enumerates the device driver DirectIo64.sys to obtain a handle for communication.\u003c/li\u003e\n\u003cli\u003eAttacker identifies the specific IOCTL handler within the driver that facilitates physical memory interaction.\u003c/li\u003e\n\u003cli\u003eAttacker constructs a malicious payload containing an arbitrary 64-bit physical address and a targeted bit index.\u003c/li\u003e\n\u003cli\u003eAttacker sends the IOCTL request to the driver to invoke the vulnerable MmMapIoSpace function.\u003c/li\u003e\n\u003cli\u003eThe driver processes the request without validating the address range, clearing the specified bits in kernel memory.\u003c/li\u003e\n\u003cli\u003eAttacker triggers a modification to a page table entry or kernel code page to overwrite security-sensitive data structures.\u003c/li\u003e\n\u003cli\u003eAttacker gains elevated (SYSTEM) privileges on the local machine.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows local attackers to bypass Windows security controls, resulting in full system compromise. This impact is critical in enterprise environments where forensic or testing tools are deployed on sensitive endpoints.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade PassMark PerformanceTest to build 1012 or later, BurnInTest to build 1000 or later, and OSForensics to build 1016 or later immediately.\u003c/li\u003e\n\u003cli\u003eAudit for the existence of DirectIo64.sys across the enterprise to identify vulnerable hosts.\u003c/li\u003e\n\u003cli\u003eRestrict access to diagnostic and forensic tools to authorized administrators only.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-04T19:27:10Z","date_published":"2026-09-04T19:27:10Z","id":"https://feed.craftedsignal.io/briefs/2026-09-passmark-privilege-escalation/","summary":"PassMark PerformanceTest, BurnInTest, and OSForensics contain a vulnerability in the DirectIo64.sys driver that allows local users to clear arbitrary physical memory bits, enabling privilege escalation.","title":"Local Privilege Escalation in PassMark Software Drivers","url":"https://feed.craftedsignal.io/briefs/2026-09-passmark-privilege-escalation/"}],"language":"en","title":"CraftedSignal Threat Feed - OSForensics (\u003c 11.1 Build 1016)","version":"https://jsonfeed.org/version/1.1"}