CVE-2026-80116

Summary

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that allows local users to modify hardware configuration by exploiting exposed IOCTLs with no validation on device selection, register offset, or value. Attackers can obtain a device handle and issue arbitrary PCI configuration space read/write operations to enable Bus Master DMA on any PCI device, halt storage controller I/O by clearing command registers, or remap Base Address Registers to redirect DMA to an attacker-chosen physical address.

Affected Software

VendorProductVersion RangeStatus
PassMark SoftwarePerformanceTest0 < 11.1 build 1012affected
PassMark SoftwareBurnInTest0 < 11.1 build 1000affected
PassMark SoftwareOSForensics0 < 11.1 build 1016affected

Weaknesses

  • CWE-782: Exposed IOCTL with Insufficient Access Control

References