CVE-2026-80113: PassMark PerformanceTest, BurnInTest, and OSForensics Arbitrary Bit Clear via DirectIo64.sys IOCTL
PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that allows local users to clear arbitrary bits at any physical memory address due to missing validation of the physical address parameter in an exposed IOCTL handler. Attackers can obtain a device handle and supply an arbitrary 64-bit physical address with a bit index to invoke MmMapIoSpace and clear bits in kernel code pages or page table entries, enabling local privilege escalation or system compromise.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
DirectIo64.sys (bundled with PassMark PerformanceTest, BurnInTest, OSForensics)to a version that resolves this vulnerability.Fixed in 11.1 build 1012 - Upgrade
Upgrade
DirectIo64.sys (bundled with PassMark PerformanceTest, BurnInTest, OSForensics)to a version that resolves this vulnerability.Fixed in 11.1 build 1000 - Upgrade
Upgrade
DirectIo64.sys (bundled with PassMark PerformanceTest, BurnInTest, OSForensics)to a version that resolves this vulnerability.Fixed in 11.1 build 1016
Event History
Frequently Asked Questions
Which installations are affected?
Affected versions are PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016. The issue is in the DirectIo64.sys driver used by these products.
What level of access does an attacker need?
An attacker needs local access and low-level privileges sufficient to obtain a handle to the exposed device. No user interaction is required.
What can exploitation achieve?
An attacker can provide an arbitrary 64-bit physical address and bit index to clear bits in kernel code pages or page table entries. This can enable local privilege escalation or full system compromise.
How can I determine whether a system is exposed?
Check whether PerformanceTest, BurnInTest, or OSForensics is installed and compare its version and build number with the fixed thresholds. Systems running earlier builds of the affected products should be treated as vulnerable.