PassMark PerformanceTest 早于 11.1 版本(build 1012)以及 BurnInTest 早于 11.1 版本(build 1000)和 OSForensics 早于 11.1 版本(build 1016),其 DirectIo64.sys 驱动存在权限提升漏洞。该漏洞源于对设备选择、寄存器偏移量和写入值缺乏验证的未防护 I/O 控制字(IOCTL),使得本地用户能够修改硬件配置。攻击者可获取设备句柄并发出任意的 PCI 配置空间读/写操作,从而可以在任意 PCI 设备上启用总线主控
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| PassMark Software | BurnInTest | < 11.1 build 1000 |
affected |
| PassMark Software | OSForensics | < 11.1 build 1016 |
affected |
| PassMark Software | PerformanceTest | < 11.1 build 1012 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| PassMark Software | PerformanceTest | 0 ~ 11.1 build 1012 | - |
|
| PassMark Software | BurnInTest | 0 ~ 11.1 build 1000 | - |
|
| PassMark Software | OSForensics | 0 ~ 11.1 build 1016 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-80114 | 7.8 HIGH | PassMark PerformanceTest, BurnInTest, and OSForensics Hard-coded Credentials Authenticatio |
| CVE-2026-80119 | 7.8 HIGH | PassMark PerformanceTest, BurnInTest, and OSForensics Physical Memory Disclosure via Direc |
| CVE-2026-80112 | 7.8 HIGH | PassMark PerformanceTest, BurnInTest, and OSForensics Improper Access Control via DirectIo |
| CVE-2026-80113 | 7.1 HIGH | PassMark PerformanceTest, BurnInTest, and OSForensics Arbitrary Bit Clear via DirectIo64.s |
| CVE-2026-80117 | 7.1 HIGH | PassMark PerformanceTest, BurnInTest, and OSForensics Arbitrary I/O Port Access via Direct |
| CVE-2026-80118 | 7.1 HIGH | PassMark PerformanceTest, BurnInTest, and OSForensics Kernel Null Pointer Dereference via |
| CVE-2026-80115 | 6.1 MEDIUM | PassMark PerformanceTest, BurnInTest, and OSForensics Kernel Crash via DirectIo64.sys MSR |
No comments yet