CVE-2024-36348

Eine vorübergehende Ausführungsschwachstelle in einigen AMD-Prozessoren kann es einem Benutzerprozess ermöglichen, die Steuerregister spe…

Description

A transient execution vulnerability in some AMD processors may allow a user process to infer the control registers speculatively even if UMIP feature is enabled, potentially resulting in information leakage.

Metrics

3.8
Source: cna-v3
25.4 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
Show all metrics
Severity
low
no public PoC known
0.3 %
Low — model estimates < 1% exploitation likelihood.
Published
2025-07-08 16:42 UTC
CWE-1420

Weakness classes (CWE)

  • CWE-1420Base

    Exposure of Sensitive Information during Transient Execution

    A processor event or prediction may allow incorrect operations (or correct operations with incorrect data) to execute transiently, potentially exposing data over a covert channel.

    cwe.mitre.org →

References & sources

Linked advisories