Privilege Escalation Vulnerability in PassMark PerformanceTest, BurnInTest, and OSForensics
CVE-2026-80113

6.9MEDIUM

Key Information:

Vendor
CVE Published:
4 September 2026

Badges

👾 Exploit Exists

What is CVE-2026-80113?

A local privilege escalation vulnerability exists in DirectIo64.sys, affecting various PassMark products. This flaw allows attackers to exploit missing validation in the physical address parameter of an exposed IOCTL handler. By obtaining a device handle, local users can supply arbitrary 64-bit physical addresses to clear bits from kernel code pages or page table entries, potentially leading to system compromise. Users of PerformanceTest, BurnInTest, and OSForensics should ensure that they are using the latest builds to mitigate this risk.

Affected Version(s)

BurnInTest 0

OSForensics 0

PerformanceTest 0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Emil Sørbrøden
.