CVE-2026-80112: PassMark PerformanceTest, BurnInTest, and OSForensics Improper Access Control via DirectIo64.sys
PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an improper access control vulnerability in the DirectIo64.sys kernel driver that allows unprivileged local users to perform privileged hardware operations by opening a handle to the device object created without a security descriptor. Attackers can issue IOCTLs through the permissive default Windows ACL applied to the device to access restricted hardware operations regardless of privilege or integrity level.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
PassMark PerformanceTestto a version that resolves this vulnerability.Fixed in 11.1 build 1012 - Upgrade
Upgrade
BurnInTestto a version that resolves this vulnerability.Fixed in 11.1 build 1000 - Upgrade
Upgrade
OSForensicsto a version that resolves this vulnerability.Fixed in 11.1 build 1016
Event History
Frequently Asked Questions
Who can exploit this issue?
Any unprivileged local user who can access the affected DirectIo64.sys device object can exploit it. Remote access and user interaction are not required, but the attacker needs local code execution.
Are default installations affected?
Yes. The driver creates its device object without a security descriptor, causing Windows to apply a permissive default ACL. This allows access regardless of the user's privilege or integrity level.
Which product versions need remediation?
PerformanceTest releases before 11.1 build 1012, BurnInTest releases before 11.1 build 1000, and OSForensics releases before 11.1 build 1016 are affected.
What could an attacker do through the vulnerable driver?
An attacker can open a handle to the driver and issue IOCTL requests for privileged or restricted hardware operations. The reported impact includes compromise of confidentiality, integrity, and availability.