PT-2026-86227 · Passmark · Performancetest+2

·

CVE-2026-80114

·

Published

2026-09-04

·

Updated

2026-09-09

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PassMark PerformanceTest versions prior to 11.1 build 1012 BurnInTest versions prior to 11.1 build 1000 OSForensics versions prior to 11.1 build 1016
Description The DirectIo64.sys driver contains hard-coded credentials. Local attackers can extract an 8-byte key embedded as a literal in the binary to compute valid MD5 authentication tags for arbitrary IOCTL write requests, enabling arbitrary physical memory writes. Furthermore, attackers can bypass secondary validation gates by using the driver's bit-clear IOCTL to modify a bit in the gating instruction's displacement byte. This action causes subsequent write requests to bypass MAC verification, size checks, and Vendor ID checks.
Recommendations Update PassMark PerformanceTest to version 11.1 build 1012 or later. Update BurnInTest to version 11.1 build 1000 or later. Update OSForensics to version 11.1 build 1016 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-80114

Affected Products

Burnintest
Osforensics
Performancetest