Куда я попал?
SECURITM это SGRC система, ? автоматизирующая процессы в службах информационной безопасности. SECURITM помогает построить и управлять ИСПДн, КИИ, ГИС, СМИБ/СУИБ, банковскими системами защиты.
А еще SECURITM это место для обмена опытом и наработками для служб безопасности.

CVE-2026-80118

PUBLISHED 10.09.2026

CNA: VulnCheck

PassMark PerformanceTest, BurnInTest, and OSForensics Kernel Null Pointer Dereference via DirectIo64.sys IOCTL

Обновлено: 04.09.2026
PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an unauthenticated physical memory disclosure in DirectIo64.sys, reachable by unprivileged local users through a single IOCTL with no caller-identity check. The handler writes a crash-dump-format (PAGEDU64) image of all physical memory to a caller-supplied file path in the SYSTEM context, allowing a standard user to create files in locations they cannot otherwise write and to recover memory belonging to processes of other users. The image is preceded by a header that exposes the kernel loaded-module list, active-process list and PFN database pointers, defeating KASLR. The same handler also dereferences the return value of an internal kernel-structure locator without a NULL check; that locator returns NULL on three distinct failure paths, and a kernel crash results on builds where any of those paths is taken.

CWE

Идентификатор Описание
CWE-476 The product dereferences a pointer that it expects to be valid but is NULL.
CWE-497 The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.
CWE-73 The product allows user input to control or influence paths or file names that are used in filesystem operations.

CVSS

Оценка Severity Версия Базовый вектор
8.4 HIGH 4.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
7.1 HIGH 3.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

EPSS

Вероятность Severity Процентиль ? Дата расчёта
0.11% LOW 1.67 17.09.2026

Доп. Информация

Product Status

PerformanceTest
Product: PerformanceTest
Vendor: PassMark Software
Default status: affected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0 до 11.1 build 1012 affected
BurnInTest
Product: BurnInTest
Vendor: PassMark Software
Default status: affected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0 до 11.1 build 1000 affected
OSForensics
Product: OSForensics
Vendor: PassMark Software
Default status: affected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0 до 11.1 build 1016 affected
 

Ссылки

CISA ADP Vulnrichment

Обновлено: 10.09.2026
Этот блок содержит дополнительную информацию, предоставленную программой CVE для этой уязвимости.

SSVC

Exploitation Automatable Technical Impact Версия Дата доступа
poc no total 2.0.3 10.09.2026

Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.