Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-80118— PassMark PerformanceTest, BurnInTest, and OSForensics Kernel Null Pointer Dereference via DirectIo64.sys IOCTL

Quick assessment

Affected
PassMark Software PerformanceTest
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

PassMark PerformanceTest 11.1 build 1012 之前版本、BurnInTest 11.1 build 1000 之前版本以及 OSForensics 11.1 build 1016 之前版本中,其组件 存在一个未认证的物理内存泄露漏洞。该漏洞可被非特权本地用户通过单个 IOCTL 调用触发,且驱动在处理器中未对调用者身份进行校验。 该处理函数会在 SYSTEM 上下文中,将一个包含所有物理内存的崩溃转储格式(PAGEDU64)镜像文件写入由调用者指定的文件路径。这使得标准用户能够在

CVSS 7.1 · High

Possible ATT&CK Techniques 2 AI

T1015 T1069 · Permission Groups Discovery

Affected Version Matrix 3

VendorProduct Version RangeStatus
PassMark Software BurnInTest < 11.1 build 1000 affected
PassMark Software OSForensics < 11.1 build 1016 affected
PassMark Software PerformanceTest < 11.1 build 1012 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-80118

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
PassMark PerformanceTest, BurnInTest, and OSForensics Kernel Null Pointer Dereference via DirectIo64.sys IOCTL
Source: CVE Program / CVE List V5
Vulnerability Description
PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an unauthenticated physical memory disclosure in DirectIo64.sys, reachable by unprivileged local users through a single IOCTL with no caller-identity check. The handler writes a crash-dump-format (PAGEDU64) image of all physical memory to a caller-supplied file path in the SYSTEM context, allowing a standard user to create files in locations they cannot otherwise write and to recover memory belonging to processes of other users. The image is preceded by a header that exposes the kernel loaded-module list, active-process list and PFN database pointers, defeating KASLR. The same handler also dereferences the return value of an internal kernel-structure locator without a NULL check; that locator returns NULL on three distinct failure paths, and a kernel crash results on builds where any of those paths is taken.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
空指针解引用
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
PassMark Software PerformanceTest 0 ~ 11.1 build 1012 -
PassMark Software BurnInTest 0 ~ 11.1 build 1000 -
PassMark Software OSForensics 0 ~ 11.1 build 1016 -

II. Public POCs for CVE-2026-80118

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-80118

登录查看更多情报信息。

Vendor Advisories for CVE-2026-80118 (1)

Proof of Concept for CVE-2026-80118 (1)

Security Blog Posts for CVE-2026-80118 (1)

Vendor Pages for CVE-2026-80118 (2)

Same Patch Batch · PassMark Software · 2026-09-04 · 8 CVEs total

CVE-2026-80116 7.8 HIGH PassMark PerformanceTest, BurnInTest, and OSForensics Privilege Escalation via DirectIo64.
CVE-2026-80114 7.8 HIGH PassMark PerformanceTest, BurnInTest, and OSForensics Hard-coded Credentials Authenticatio
CVE-2026-80119 7.8 HIGH PassMark PerformanceTest, BurnInTest, and OSForensics Physical Memory Disclosure via Direc
CVE-2026-80112 7.8 HIGH PassMark PerformanceTest, BurnInTest, and OSForensics Improper Access Control via DirectIo
CVE-2026-80113 7.1 HIGH PassMark PerformanceTest, BurnInTest, and OSForensics Arbitrary Bit Clear via DirectIo64.s
CVE-2026-80117 7.1 HIGH PassMark PerformanceTest, BurnInTest, and OSForensics Arbitrary I/O Port Access via Direct
CVE-2026-80115 6.1 MEDIUM PassMark PerformanceTest, BurnInTest, and OSForensics Kernel Crash via DirectIo64.sys MSR

IV. Related Vulnerabilities

V. Comments for CVE-2026-80118

No comments yet


Leave a comment