CVE-2026-80117
Received Received - Intake

Privilege Escalation in PassMark PerformanceTest via DirectIo64.sys

Vulnerability report for CVE-2026-80117, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-04

Last updated on: 2026-09-04

Assigner: VulnCheck

Description

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that allows local users to issue arbitrary IN and OUT instructions to any x86 I/O port due to missing allowlist or port validation on exposed IOCTLs. Attackers can obtain a device handle and write to sensitive ports including the PS/2 controller port, CPU reset ports, CMOS configuration ports, and interrupt controller ports to cause an immediate system reset or other hardware-level manipulation from a standard user account.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-04
Last Modified
2026-09-04
Generated
2026-09-05
AI Q&A
2026-09-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
passmark performancetest to 11.1.1012 (exc)
passmark burnintest to 11.1.1000 (exc)
passmark osforensics to 11.1.1016 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-782 The product implements an IOCTL with functionality that should be restricted, but it does not properly enforce access control for the IOCTL.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a privilege escalation flaw in PassMark PerformanceTest, BurnInTest, and OSForensics software versions before 11.1 build 1012, 1000, and 1016 respectively. It involves a driver file named DirectIo64.sys that fails to validate I/O port access requests. Attackers with local access can exploit this to send arbitrary commands to hardware ports, potentially causing system resets or hardware manipulation from a standard user account.

Detection Guidance

This vulnerability is specific to PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016. Check installed versions of these software on your system. Look for the presence of DirectIo64.sys driver in system directories.

Impact Analysis

If exploited, this vulnerability allows attackers to perform hardware-level attacks such as forcing system resets, modifying CMOS settings, or interfering with the CPU and interrupt controller. This could lead to data loss, system instability, or unauthorized hardware changes. The impact is severe as it enables deep system control from a low-privilege account.

Compliance Impact

This vulnerability could lead to unauthorized system access and hardware manipulation, violating data integrity and confidentiality requirements in GDPR and HIPAA. Organizations using affected PassMark software may face compliance violations due to insufficient protection against privilege escalation attacks that compromise system security.

Mitigation Strategies

Update PassMark PerformanceTest to version 11.1 build 1012 or later, BurnInTest to version 11.1 build 1000 or later, and OSForensics to version 11.1 build 1016 or later. Remove or disable the vulnerable DirectIo64.sys driver if it is present on your system.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-80117. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart