Privilege Escalation and Denial-of-Service in PassMark PerformanceTest, BurnInTest, and OSForensics
CVE-2026-80115

6.9MEDIUM

Key Information:

Vendor
CVE Published:
4 September 2026

Badges

👾 Exploit Exists

What is CVE-2026-80115?

Certain versions of PassMark software, including PerformanceTest, BurnInTest, and OSForensics, contain a serious vulnerability in the DirectIo64.sys driver, which permits local attackers to read unauthorized Model-Specific Registers or to issue zero writes to critical values. This exploitation is made possible through insufficient enforcement of blocklists on exposed IOCTLs. An attacker can exploit these weaknesses to zero out the system call handler MSR, leading to a system crash that is unrecoverable upon executing the next system call, or to read sensitive MSRs that could expose kernel data structures.

Affected Version(s)

BurnInTest 0

OSForensics 0

PerformanceTest 0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Emil Sørbrøden
.