CVE-2026-80119
Last modified
CVE-2026-80119 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an information disclosure vulnerability in DirectIo64.sys that allows unauthenticated local attackers to dump complete physical memory contents by supplying a caller-controlled file path to an exposed IOCTL. Attackers can issue a single IOCTL call to trigger the driver to iterate all physical memory ranges via MmGetPhysicalMemoryRanges and map each page through ZwMapViewOfSection on the PhysicalMemory section object, writing a full RAM image to an attacker-specified path in the SYSTEM context, bypassing user-mode ACLs and exposing LSASS working set, process memory, and cryptographic material from all running processes.. EPSS estimates a 0.13% chance of exploitation in the next 30 days.
Description
PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an information disclosure vulnerability in DirectIo64.sys that allows unauthenticated local attackers to dump complete physical memory contents by supplying a caller-controlled file path to an exposed IOCTL. Attackers can issue a single IOCTL call to trigger the driver to iterate all physical memory ranges via MmGetPhysicalMemoryRanges and map each page through ZwMapViewOfSection on the PhysicalMemory section object, writing a full RAM image to an attacker-specified path in the SYSTEM context, bypassing user-mode ACLs and exposing LSASS working set, process memory, and cryptographic material from all running processes.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| PassMark Software | PerformanceTest | < 11.1 build 1012 |
| PassMark Software | BurnInTest | < 11.1 build 1000 |
| PassMark Software | OSForensics | < 11.1 build 1016 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-80119?
How severe is CVE-2026-80119?
How do I fix CVE-2026-80119?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-80113PassMark PerformanceTest before 11.1 build 1012, BurnInTest …7.1
- CVE-2026-80114PassMark PerformanceTest before 11.1 build 1012, BurnInTest …7.8
- CVE-2026-80115PassMark PerformanceTest before 11.1 build 1012, BurnInTest …6.1
- CVE-2026-80116PassMark PerformanceTest before 11.1 build 1012, BurnInTest …7.8
- CVE-2026-80117PassMark PerformanceTest before 11.1 build 1012, BurnInTest …7.1
- CVE-2026-80118PassMark PerformanceTest before 11.1 build 1012, BurnInTest …7.1
- CVE-2026-8012Inappropriate implementation in MHTML in Google Chrome prior…5.4
- CVE-2026-80125Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell…5.9
- CVE-2026-80126Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell…6.5
- CVE-2026-80127Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell…7.2
- CVE-2026-80128Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell…6.4
- CVE-2026-80129Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell…6.5
Are you affected by CVE-2026-80119?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
