---
id: CVE-2026-80112
title: >-
  PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build
  1000, and OSForensics before 11.1 build 1016 contain an improper access
  control vulnerability in the DirectIo64.sys kernel driver that allows
  unprivileged loca…
summary: >-
  PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build
  1000, and OSForensics before 11.1 build 1016 contain an improper access
  control vulnerability in the DirectIo64.sys kernel driver that allows
  unprivileged loca…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-732
published: '2026-09-04'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:10:30.270'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-80112'
references:
  - url: 'https://dkom.dev/posts/directio64-disclosure/'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/floppywiggler/directio64-disclosure'
    label: disclosure@vulncheck.com
  - url: 'https://www.osforensics.com/whats-new.html'
    label: disclosure@vulncheck.com
  - url: 'https://www.passmark.com/products/burnintest/history.php'
    label: disclosure@vulncheck.com
  - url: 'https://www.passmark.com/products/performancetest/history.php'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/passmark-performancetest-burnintest-and-osforensics-improper-access-control-via-directio64-sys
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00149
epssPercentile: 0.03425
ingestedAt: '2026-09-08T21:11:12.295Z'
---

## Overview

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an improper access control vulnerability in the DirectIo64.sys kernel driver that allows unprivileged local users to perform privileged hardware operations by opening a handle to the device object created without a security descriptor. Attackers can issue IOCTLs through the permissive default Windows ACL applied to the device to access restricted hardware operations regardless of privilege or integrity level.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
