CVE-2025-35979CWE-1423

Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution for some Intel(R) Processors within…

Medium · published May 12, 2026

CVSS v4.0
6.8
EPSS
0%
Percentile
0.8
In the wild
Unconfirmed
What it is

Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution for some Intel(R) Processors within VMX non-root (guest) operation may allow an information disclosure. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (none) and availability (none) impacts.

The record
Technical detail
CVSS v4.0
6.8 · MEDIUM
Vector
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
EPSS
0.00096 · 0.8th percentile
Weakness
CWE-1423 · Exposure of Sensitive Information caused by Shared Microarchitectural Predictor State that Influences Transient Execution
Published
2026-05-12T16:35Z
EPSS history
Timeline
  • 12 MAY 16:35Z
    Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution for some Intel(R) Processors within…
    cvelistv5