CVE-2026-80116

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that allows local users to modify hardware configuration by exploiting exposed IOCTLs with no validation on device selection, register offset, or value. Attackers can obtain a device handle and issue arbitrary PCI configuration space read/write operations to enable Bus Master DMA on any PCI device, halt storage controller I/O by clearing command registers, or remap Base Address Registers to redirect DMA to an attacker-chosen physical address.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-04 19:17

Updated : 2026-09-08 20:10


NVD link : CVE-2026-80116

Mitre link : CVE-2026-80116

CVE.ORG link : CVE-2026-80116


JSON object : View

Products Affected

No product.

CWE
CWE-782

Exposed IOCTL with Insufficient Access Control