Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-80114— PassMark PerformanceTest, BurnInTest, and OSForensics Hard-coded Credentials Authentication Bypass via DirectIo64.sys

Quick assessment

Affected
PassMark Software PerformanceTest
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

PassMark PerformanceTest 早于 11.1 build 1012 版本、BurnInTest 早于 11.1 build 1000 版本,以及 OSForensics 早于 11.1 build 1016 版本,均存在一个在 驱动中的硬编码凭证漏洞。该漏洞允许本地攻击者通过从分发的二进制文件中提取作为硬编码字面量嵌入的 8 字节密钥,计算任意 IOCTL 写入请求的有效 MD5 认证标签,从而执行任意的物理内存写入操作。 此外,攻击者还可以使用驱动程序自身的“位清除”IOCTL 接口,清除门控

CVSS 7.8 · High

Affected Version Matrix 3

VendorProduct Version RangeStatus
PassMark Software BurnInTest < 11.1 build 1000 affected
PassMark Software OSForensics < 11.1 build 1016 affected
PassMark Software PerformanceTest < 11.1 build 1012 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-80114

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
PassMark PerformanceTest, BurnInTest, and OSForensics Hard-coded Credentials Authentication Bypass via DirectIo64.sys
Source: CVE Program / CVE List V5
Vulnerability Description
PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a hard-coded credentials vulnerability in DirectIo64.sys that allows local attackers to perform arbitrary physical memory writes by extracting an 8-byte key embedded as a hardcoded literal in the distributed binary and computing valid MD5 authentication tags for arbitrary IOCTL write requests. Attackers can additionally bypass a secondary validation gate by using the driver's own bit-clear IOCTL to clear a single bit in the gating instruction's displacement byte, causing all subsequent write requests to skip MAC verification, size checks, and Vendor ID checks entirely.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
使用硬编码的密码学密钥
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
PassMark Software PerformanceTest 0 ~ 11.1 build 1012 -
PassMark Software BurnInTest 0 ~ 11.1 build 1000 -
PassMark Software OSForensics 0 ~ 11.1 build 1016 -

II. Public POCs for CVE-2026-80114

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-80114

登录查看更多情报信息。

Vendor Advisories for CVE-2026-80114 (1)

Proof of Concept for CVE-2026-80114 (1)

Security Blog Posts for CVE-2026-80114 (1)

Vendor Pages for CVE-2026-80114 (2)

Same Patch Batch · PassMark Software · 2026-09-04 · 8 CVEs total

CVE-2026-80116 7.8 HIGH PassMark PerformanceTest, BurnInTest, and OSForensics Privilege Escalation via DirectIo64.
CVE-2026-80119 7.8 HIGH PassMark PerformanceTest, BurnInTest, and OSForensics Physical Memory Disclosure via Direc
CVE-2026-80112 7.8 HIGH PassMark PerformanceTest, BurnInTest, and OSForensics Improper Access Control via DirectIo
CVE-2026-80113 7.1 HIGH PassMark PerformanceTest, BurnInTest, and OSForensics Arbitrary Bit Clear via DirectIo64.s
CVE-2026-80117 7.1 HIGH PassMark PerformanceTest, BurnInTest, and OSForensics Arbitrary I/O Port Access via Direct
CVE-2026-80118 7.1 HIGH PassMark PerformanceTest, BurnInTest, and OSForensics Kernel Null Pointer Dereference via
CVE-2026-80115 6.1 MEDIUM PassMark PerformanceTest, BurnInTest, and OSForensics Kernel Crash via DirectIo64.sys MSR

IV. Related Vulnerabilities

V. Comments for CVE-2026-80114

No comments yet


Leave a comment