CVE-2020-15479
Summary
| CVE | CVE-2020-15479 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-08-07 21:15:00 UTC |
| Updated | 2020-08-12 16:07:00 UTC |
| Description | An issue was discovered in PassMark BurnInTest through 9.1, OSForensics through 7.1, and PerformanceTest through 10. The driver's IOCTL request handler attempts to copy the input buffer onto the stack without checking its size and can cause a buffer overflow. This could lead to arbitrary Ring-0 code execution and escalation of privileges. This affects DirectIo32.sys and DirectIo64.sys. |
Risk And Classification
Problem Types: CWE-120
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Passmark | Burnintest | All | All | All | All |
| Application | Passmark | Osforensics | All | All | All | All |
| Application | Passmark | Performancetest | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| vulnerability-disclosures/CVE-2020-15479.md at master · eset/vulnerability-disclosures · GitHub | MISC | github.com | Exploit, Third Party Advisory |
| GitHub - eset/vulnerability-disclosures: Repository of vulnerabilities disclosed by ESET | MISC | github.com | Third Party Advisory |
| PassMark Support Home Page | MISC | www.passmark.com | Vendor Advisory |
| PassMark.com :: Index | MISC | www.passmark.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.