PassMark PerformanceTest 11.1 build 1012 之前、BurnInTest 11.1 build 1000 之前,以及 OSForensics 11.1 build 1016 之前的版本中,其 DirectIo64.sys 内核驱动程序存在一个不当访问控制漏洞。该漏洞允许未授权的本地用户通过打开一个未设置安全描述符而创建的设备对象句柄,从而执行特权硬件操作。攻击者可以通过应用于该设备的宽松默认 Windows ACL,发送 IOCTL 来访问受限的硬件操作,而不受权限或完整性级别的
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| PassMark Software | BurnInTest | < 11.1 build 1000 |
affected |
| PassMark Software | OSForensics | < 11.1 build 1016 |
affected |
| PassMark Software | PerformanceTest | < 11.1 build 1012 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| PassMark Software | PerformanceTest | 0 ~ 11.1 build 1012 | - |
|
| PassMark Software | BurnInTest | 0 ~ 11.1 build 1000 | - |
|
| PassMark Software | OSForensics | 0 ~ 11.1 build 1016 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-80116 | 7.8 HIGH | PassMark PerformanceTest, BurnInTest, and OSForensics Privilege Escalation via DirectIo64. |
| CVE-2026-80114 | 7.8 HIGH | PassMark PerformanceTest, BurnInTest, and OSForensics Hard-coded Credentials Authenticatio |
| CVE-2026-80119 | 7.8 HIGH | PassMark PerformanceTest, BurnInTest, and OSForensics Physical Memory Disclosure via Direc |
| CVE-2026-80113 | 7.1 HIGH | PassMark PerformanceTest, BurnInTest, and OSForensics Arbitrary Bit Clear via DirectIo64.s |
| CVE-2026-80117 | 7.1 HIGH | PassMark PerformanceTest, BurnInTest, and OSForensics Arbitrary I/O Port Access via Direct |
| CVE-2026-80118 | 7.1 HIGH | PassMark PerformanceTest, BurnInTest, and OSForensics Kernel Null Pointer Dereference via |
| CVE-2026-80115 | 6.1 MEDIUM | PassMark PerformanceTest, BurnInTest, and OSForensics Kernel Crash via DirectIo64.sys MSR |
No comments yet