CVE-2026-80115: PassMark PerformanceTest, BurnInTest, and OSForensics Kernel Crash via DirectIo64.sys MSR Write IOCTL

Published Sep 4, 2026
·
Updated

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation and denial-of-service vulnerability in DirectIo64.sys that allows local attackers to read arbitrary Model-Specific Registers or write zero to any MSR through exposed IOCTLs with insufficient blocklist enforcement. Attackers can exploit the unrestricted write IOCTL to zero out the system call handler MSR, causing an immediate unrecoverable kernel crash on the next system call, or read security-sensitive MSRs used to locate kernel data structures.

Affected Software

3 affected components
PassMark Software PerformanceTest<11.1 build 1012
PassMark Software BurnInTest<11.1 build 1000
PassMark Software OSForensics<11.1 build 1016

Event History

Sep 4, 2026
CVE Published
via MITRE·06:35 PM
Data Sourced
via MITRE·06:35 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What access does an attacker need to trigger the issue?

The attack is local and requires low privileges. No user interaction is required.

2

Which product releases are affected?

Affected releases are PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016.

3

What is the practical impact of successful exploitation?

An attacker can write zero to the system call handler MSR, causing an immediate unrecoverable kernel crash when the next system call occurs. They can also read arbitrary MSRs, including security-sensitive registers that may help locate kernel data structures.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203