PT-2026-86229 · Passmark · Osforensics+2

·

CVE-2026-80116

·

Published

2026-09-04

·

Updated

2026-09-05

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PassMark PerformanceTest versions prior to 11.1 build 1012 BurnInTest versions prior to 11.1 build 1000 OSForensics versions prior to 11.1 build 1016
Description A privilege escalation issue exists in the DirectIo64.sys driver. Local users can modify hardware configuration by exploiting exposed IOCTLs (Input/Output Control codes used by applications to communicate with device drivers) that lack validation on device selection, register offset, or value. By obtaining a device handle, an attacker can perform arbitrary PCI configuration space read/write operations. This allows for enabling Bus Master DMA (Direct Memory Access, which lets hardware devices access system memory independently of the CPU) on any PCI device, halting storage controller I/O by clearing command registers, or remapping Base Address Registers to redirect DMA to a physical address chosen by the attacker.
Recommendations Update PassMark PerformanceTest to version 11.1 build 1012 or later. Update BurnInTest to version 11.1 build 1000 or later. Update OSForensics to version 11.1 build 1016 or later.

Exploit

Fix

LPE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-80116

Affected Products

Burnintest
Osforensics
Performancetest