Description
PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that allows local users to modify hardware configuration by exploiting exposed IOCTLs with no validation on device selection, register offset, or value. Attackers can obtain a device handle and issue arbitrary PCI configuration space read/write operations to enable Bus Master DMA on any PCI device, halt storage controller I/O by clearing command registers, or remap Base Address Registers to redirect DMA to an attacker-chosen physical address.
Published: 2026-09-04
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Patch Now
AI Analysis

Impact

The vulnerability in DirectIo64.sys enables local users to modify hardware configuration via unvalidated IOCTL calls. By obtaining a device handle, an attacker can perform arbitrary PCI configuration space read and write operations, allowing the enabling of Bus Master DMA on any PCI device, the disabling of storage controller I/O, or the remapping of Base Address Registers to redirect DMA traffic to an attacker‑chosen address.

Affected Systems

Affected are PassMark Software products: BurnInTest (versions prior to 11.1 build 1000), OSForensics (versions prior to 11.1 build 1016) and PerformanceTest (versions prior to 11.1 build 1012).

Risk and Exploitability

The CVSS score is 8.5 indicating high severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. Attack requires local execution; any user who can run the affected applications may exploit the flaw. The lack of validation on device selection, register offset, and value means an attacker can impersonate privileged operations on hardware, compromising the integrity and availability of device configuration.

Generated by OpenCVE AI on September 4, 2026 at 20:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade BurnInTest, OSForensics, and PerformanceTest to the latest patched versions where the DirectIo64.sys flaw is resolved.
  • Restrict local user accounts that can launch these utilities so that only trusted administrators have the ability to run them.
  • If possible, disable or reset Bus Master DMA and reset PCI configuration for devices until the software can be updated, to prevent the attacker from persisting changes.

Generated by OpenCVE AI on September 4, 2026 at 20:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 07 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Passmark
Passmark burnintest
Passmark osforensics
Passmark performancetest
Vendors & Products Passmark
Passmark burnintest
Passmark osforensics
Passmark performancetest

Fri, 04 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that allows local users to modify hardware configuration by exploiting exposed IOCTLs with no validation on device selection, register offset, or value. Attackers can obtain a device handle and issue arbitrary PCI configuration space read/write operations to enable Bus Master DMA on any PCI device, halt storage controller I/O by clearing command registers, or remap Base Address Registers to redirect DMA to an attacker-chosen physical address.
Title PassMark PerformanceTest, BurnInTest, and OSForensics Privilege Escalation via DirectIo64.sys IOCTL
Weaknesses CWE-782
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Passmark Burnintest Osforensics Performancetest
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-08T17:47:40.413Z

Reserved: 2026-08-25T19:56:44.777Z

Link: CVE-2026-80116

cve-icon Vulnrichment

Updated: 2026-09-08T17:47:33.129Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-04T19:17:28.420

Modified: 2026-09-08T20:10:30.270

Link: CVE-2026-80116

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T08:15:14Z

Weaknesses
  • CWE-782

    Exposed IOCTL with Insufficient Access Control