CVE-2024-36348CWE-1420

A transient execution vulnerability in some AMD processors may allow a user process to infer the control registers speculatively even if UMIP feature is…

Low · published July 8, 2025

CVSS v3.1
3.8
EPSS
0%
Percentile
20.9
In the wild
Unconfirmed
What it is

A transient execution vulnerability in some AMD processors may allow a user process to infer the control registers speculatively even if UMIP feature is enabled, potentially resulting in information leakage.

The record
Technical detail
CVSS v3.1
3.8 · LOW
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00287 · 20.9th percentile
Weakness
CWE-1420 · Exposure of Sensitive Information during Transient Execution
Published
2025-07-08T16:42Z
EPSS history
Timeline
  • 08 JUL 16:42Z
    A transient execution vulnerability in some AMD processors may allow a user process to infer the control registers speculatively even if UMIP feature is…
    cvelistv5