ZeroHour

CVE-2026-80112

moderate

Improper Access Control in PassMark DirectIo64.sys Driver Grants Privileged IOCTL Access

CVSS 4.0
8.5 high
EPSS
<1%p1
Published
()
Modified
AI analysis

An improper access control flaw (CWE-732) exists in the DirectIo64.sys kernel driver shipped with PassMark PerformanceTest, BurnInTest, and OSForensics: the driver creates its device object without a security descriptor, so the permissive default Windows ACL applies. Any unprivileged local user can therefore open a handle to the device and issue IOCTLs that perform restricted, privileged hardware operations, regardless of the caller's privilege or integrity level. Successful abuse effectively gives a low-privileged local account elevated hardware access on the affected machine, consistent with the CVSS 4.0 score of 8.5, which rates high impact to confidentiality, integrity, and availability on the vulnerable system. Users running affected versions of any of the three Windows tools are exposed, with the greatest risk on shared or multi-user machines where untrusted local accounts can log in. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is reported, and EPSS currently estimates only a 0.1% probability of exploitation in the next 30 days.

What to do: Upgrade to PerformanceTest 11.1 build 1012 or later, BurnInTest 11.1 build 1000 or later, and OSForensics 11.1 build 1016 or later, each of which ships a corrected DirectIo64.sys driver. Prioritize patching shared or multi-user Windows systems (labs, test benches, forensic workstations) where untrusted local accounts can log in. As an interim measure, restrict the device object's ACL or remove/unload the driver on systems that do not actively need these tools.

Affected
PassMark Software PerformanceTestbefore 11.1 build 1012
PassMark Software BurnInTestbefore 11.1 build 1000
PassMark Software OSForensicsbefore 11.1 build 1016
Estimated exposure
moderatelikely tens of thousands of Windows installations across the three tools (estimate) — Estimate based on these being specialist desktop benchmarking, stress-testing, and forensics utilities rather than mass-market or internet-exposed software; no published active-install or scan counts are available, so treat this as an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an improper access control vulnerability in the DirectIo64.sys kernel driver that allows unprivileged local users to perform privileged hardware operations by opening a handle to the device object created without a security descriptor. Attackers can issue IOCTLs through the permissive default Windows ACL applied to the device to access restricted hardware operations regardless of privilege or integrity level.

Weakness
CWE-732
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.