CVE-2020-15480: High severity passmark burnintest vulnerability
An issue was discovered in PassMark BurnInTest through 9.1, OSForensics through 7.1, and PerformanceTest through 10. The kernel driver exposes IOCTL functionality that allows low-privilege users to read and write to arbitrary Model Specific Registers (MSRs). This could lead to arbitrary Ring-0 code execution and escalation of privileges. This affects DirectIo32.sys and DirectIo64.sys.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-15480?
CVE-2020-15480 is classified as a high severity vulnerability due to its ability to allow low-privilege users to manipulate critical system registers.
How do I fix CVE-2020-15480?
To mitigate CVE-2020-15480, ensure you update PassMark BurnInTest to version 9.2 or higher, OSForensics to version 7.2 or higher, and PerformanceTest to version 10.1 or higher.
Which software is affected by CVE-2020-15480?
CVE-2020-15480 affects PassMark BurnInTest up to version 9.1, OSForensics up to version 7.1, and PerformanceTest up to version 10.0.
What type of attack can CVE-2020-15480 enable?
CVE-2020-15480 can enable arbitrary code execution in Ring-0, potentially allowing attackers to gain elevated privileges on the system.
Can CVE-2020-15480 be exploited remotely?
CVE-2020-15480 requires local access to the system, as it involves low-privilege user interaction with the kernel driver.