CVE-2026-80115
Received Received - Intake

Privilege Escalation and DoS in PassMark PerformanceTest

Vulnerability report for CVE-2026-80115, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-04

Last updated on: 2026-09-04

Assigner: VulnCheck

Description

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation and denial-of-service vulnerability in DirectIo64.sys that allows local attackers to read arbitrary Model-Specific Registers or write zero to any MSR through exposed IOCTLs with insufficient blocklist enforcement. Attackers can exploit the unrestricted write IOCTL to zero out the system call handler MSR, causing an immediate unrecoverable kernel crash on the next system call, or read security-sensitive MSRs used to locate kernel data structures.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-04
Last Modified
2026-09-04
Generated
2026-09-05
AI Q&A
2026-09-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
passmark performancetest to 11.1_build_1012 (exc)
passmark burnintest to 11.1_build_1000 (exc)
passmark osforensics to 11.1_build_1016 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-782 The product implements an IOCTL with functionality that should be restricted, but it does not properly enforce access control for the IOCTL.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a privilege escalation and denial-of-service issue in PassMark PerformanceTest, BurnInTest, and OSForensics before versions 11.1 build 1012, 11.1 build 1000, and 11.1 build 1016 respectively. It involves a driver file DirectIo64.sys that exposes insecure IOCTLs allowing local attackers to read or write to Model-Specific Registers (MSRs) without proper restrictions.

Detection Guidance

Detecting this vulnerability requires checking for the presence of vulnerable PassMark software versions and monitoring for suspicious activity related to DirectIo64.sys. Inspect installed versions of PerformanceTest, BurnInTest, or OSForensics and ensure they are updated beyond 11.1 build 1012, 1000, or 1016 respectively. Check for unauthorized modifications to MSRs or kernel crashes.

Impact Analysis

An attacker could exploit this to crash the system by zeroing out the system call handler MSR, causing an immediate unrecoverable kernel crash. They could also read sensitive MSRs to locate critical kernel data structures, potentially leading to further exploitation or information disclosure.

Compliance Impact

This vulnerability allows local attackers to crash the kernel or read sensitive system registers, which could lead to unauthorized access or system instability. Such impacts may violate compliance requirements for data protection and system integrity in standards like GDPR and HIPAA, as they could result in unauthorized data access or service disruptions.

Mitigation Strategies

Update PassMark PerformanceTest to version 11.1 build 1012 or later, BurnInTest to version 11.1 build 1000 or later, and OSForensics to version 11.1 build 1016 or later to address the vulnerability in DirectIo64.sys.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-80115. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart