PT-2026-86232 · Passmark · Osforensics+2

·

CVE-2026-80119

·

Published

2026-09-04

·

Updated

2026-09-04

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PassMark PerformanceTest versions prior to 11.1 build 1012 BurnInTest versions prior to 11.1 build 1000 OSForensics versions prior to 11.1 build 1016
Description An information disclosure issue exists in the DirectIo64.sys driver. Unauthenticated local attackers can dump the complete contents of physical memory by providing a caller-controlled file path to an exposed IOCTL (Input/Output Control). The attack involves a single IOCTL call that triggers the driver to iterate through all physical memory ranges using the MmGetPhysicalMemoryRanges function and map each page via ZwMapViewOfSection on the PhysicalMemory section object. This process writes a full RAM image to a specified path within the SYSTEM context, bypassing user-mode Access Control Lists (ACLs) and exposing the LSASS working set, process memory, and cryptographic material from all active processes.
Recommendations Update PassMark PerformanceTest to version 11.1 build 1012 or later. Update BurnInTest to version 11.1 build 1000 or later. Update OSForensics to version 11.1 build 1016 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-80119

Affected Products

Burnintest
Osforensics
Performancetest