PT-2026-86231 · Passmark · Osforensics+2

·

CVE-2026-80118

·

Published

2026-09-04

·

Updated

2026-09-07

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions PassMark PerformanceTest versions prior to 11.1 build 1012 BurnInTest versions prior to 11.1 build 1000 OSForensics versions prior to 11.1 build 1016
Description An unauthenticated physical memory disclosure exists in the DirectIo64.sys driver. Unprivileged local users can trigger this via a single IOCTL (Input/Output Control) request that lacks caller-identity checks. The handler writes a crash-dump-format (PAGEDU64) image of all physical memory to a file path provided by the caller using the SYSTEM context. This allows a standard user to create files in restricted locations and recover memory from other users' processes. Additionally, the image includes a header exposing the kernel loaded-module list, active-process list, and PFN (Page Frame Number) database pointers, which defeats KASLR (Kernel Address Space Layout Randomization), a security feature that randomizes the memory addresses used by the kernel. The same handler also fails to perform a NULL check on the return value of an internal kernel-structure locator, which can lead to a kernel crash if the locator returns NULL on specific failure paths.
Recommendations Update PassMark PerformanceTest to version 11.1 build 1012 or later. Update BurnInTest to version 11.1 build 1000 or later. Update OSForensics to version 11.1 build 1016 or later.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-80118

Affected Products

Burnintest
Osforensics
Performancetest