CVE-2025-52347
7.8PassMark · BurnInTest, OSForensics, PerformanceTest
A vulnerability in the DirectIo64.sys component of multiple PassMark products allows local attackers to access kernel memory and escalate privileges via a crafted IOCTL call.
Executive summary
Multiple PassMark software products contain a kernel-level vulnerability that allows authenticated local attackers to escalate privileges and compromise system integrity.
Vulnerability
This vulnerability involves an improper implementation in the DirectIo64.sys driver, which permits a low-privileged local user to send a crafted IOCTL 0x8011E044 call to the driver. This action facilitates unauthorized access to kernel memory, leading to potential privilege escalation.
Business impact
Successful exploitation of this flaw allows an attacker with local access to bypass security controls and gain elevated privileges, potentially leading to full system compromise. With a CVSS score of 7.8, this vulnerability represents a significant risk to organizational endpoints, as it enables malicious actors to execute arbitrary code with kernel-level permissions, bypassing standard user protections.
Remediation
Immediate Action: Update the affected PassMark products to the latest available versions as specified in the vendor release history documentation to patch the vulnerable driver.
Proactive Monitoring: Monitor system logs for unusual kernel driver activity or unexpected attempts to interact with DirectIo64.sys using IOCTL codes.
Compensating Controls: Restrict local access to systems running these diagnostic tools and ensure that only authorized personnel can execute software with administrative or elevated privileges.
Exploitation status
Public Exploit Available: Yes — a public proof-of-concept exists in the researcher's GitHub repository linked in the official references.
Analyst recommendation
Given the potential for kernel-level privilege escalation, organizations must prioritize updating these diagnostic tools to the versions specified by PassMark. Failure to patch these components leaves local systems vulnerable to complete takeover by a malicious actor who has gained initial access to the host.