CVE-2024-36348CWE-1420
A transient execution vulnerability in some AMD processors may allow a user process to infer the control registers speculatively even if UMIP feature is…
Low · published July 8, 2025
What it is
A transient execution vulnerability in some AMD processors may allow a user process to infer the control registers speculatively even if UMIP feature is enabled, potentially resulting in information leakage.
The record
Technical detail
- CVSS v3.1
- 3.8 · LOW
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
- CVSS v4.0
- Not supplied
- EPSS
- 0.00287 · 20.9th percentile
- Weakness
- CWE-1420 · Exposure of Sensitive Information during Transient Execution
- Published
- 2025-07-08T16:42Z
EPSS history
Timeline