01642 06 11 11 Arrange Call

Buffer Overflow Vulnerability in PassMark BurnInTest, OSForensics, and PerformanceTest

CVE-2020-15479 · HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CVE-2020-15479

An issue was discovered in PassMark BurnInTest through 9.1, OSForensics through 7.1, and PerformanceTest through 10. The driver's IOCTL request handler attempts to copy the input buffer onto the stack without checking its size and can cause a buffer overflow. This could lead to arbitrary Ring-0 code execution and escalation of privileges. This affects DirectIo32.sys and DirectIo64.sys.

Learn more about our Web Application Penetration Testing UK.