CVE-2026-80118: PassMark PerformanceTest, BurnInTest, and OSForensics Kernel Null Pointer Dereference via DirectIo64.sys IOCTL

Published Sep 4, 2026
·
Updated

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an unauthenticated physical memory disclosure in DirectIo64.sys, reachable by unprivileged local users through a single IOCTL with no caller-identity check. The handler writes a crash-dump-format (PAGEDU64) image of all physical memory to a caller-supplied file path in the SYSTEM context, allowing a standard user to create files in locations they cannot otherwise write and to recover memory belonging to processes of other users. The image is preceded by a header that exposes the kernel loaded-module list, active-process list and PFN database pointers, defeating KASLR. The same handler also dereferences the return value of an internal kernel-structure locator without a NULL check; that locator returns NULL on three distinct failure paths, and a kernel crash results on builds where any of those paths is taken.

Affected Software

3 affected components
PassMark PerformanceTest<11.1 build 1012
PassMark BurnInTest<11.1 build 1000
PassMark OSForensics<11.1 build 1016

Event History

Sep 4, 2026
CVE Published
via MITRE·06:37 PM
Data Sourced
via MITRE·06:37 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

A standard unprivileged local user can reach the affected DirectIo64.sys IOCTL. No caller-identity check is performed, so administrative privileges are not required.

2

What does an attacker need to do to obtain sensitive memory contents?

The attacker needs local code execution and the ability to issue the relevant IOCTL to DirectIo64.sys with a caller-supplied output file path. The driver runs in the SYSTEM context and writes a crash-dump-format image of physical memory to that path.

3

What information can be exposed by the generated memory image?

The image can contain physical memory belonging to processes of other users. Its header also exposes pointers to the kernel loaded-module list, active-process list, and PFN database, defeating KASLR.

4

Which releases should be considered affected?

Affected releases are PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016. Systems running an earlier release of the relevant product should be updated to at least the stated build.

5

Can this issue also cause a system crash?

Yes. The IOCTL handler dereferences an internal locator result without checking for NULL, and a kernel crash occurs when any of the locator's three NULL-return failure paths is taken.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203