Privilege Escalation Threat in PassMark PerformanceTest, BurnInTest, and OSForensics
CVE-2026-80117

6.9MEDIUM

Key Information:

Vendor
CVE Published:
4 September 2026

What is CVE-2026-80117?

A privilege escalation vulnerability has been identified in DirectIo64.sys used by PassMark PerformanceTest, BurnInTest, and OSForensics. The flaw enables local users to bypass security mechanisms, allowing them to issue arbitrary IN and OUT instructions to any x86 I/O port. This occurs due to the absence of proper allowlisting and port validation on the exposed IOCTLs. Consequently, an attacker with standard user privileges can gain a device handle, manipulating sensitive hardware components. Such manipulation may lead to severe consequences, including triggering system resets or altering critical configurations, thereby undermining the integrity of the system.

Affected Version(s)

BurnInTest 0

OSForensics 0

PerformanceTest 0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Emil Sørbrøden
.