Description
Denuvo Anti-Tamper through 2026-03-04 allows bypass of a hypervisor presence check via CPUID interception (SimpleSvm.sys on AMD; hyperkd.sys and hyperhv.dll on Intel).
Published: 2026-10-02
Score: 1.9 Low
EPSS: n/a
KEV: No
Impact: Bypass hypervisor presence detection
Action: Patch
AI Analysis

Impact

Denuvo Anti‑Tamper up to 2026‑03‑04 contains a flaw that lets attackers bypass the hypervisor presence check by intercepting CPUID calls. The vulnerability stems from the CPUID interception logic in SimpleSvm.sys on AMD and hyperkd.sys and hyperhv.dll on Intel, allowing a privileged user to trick the anti‑tamper module into treating the system as if no hypervisor is running.

Affected Systems

The affected systems are installations of Irdeto’s Denuvo Anti‑Tamper, particularly versions released through 2026‑03‑04. No specific version range is listed beyond this release date.

Risk and Exploitability

The CVSS score of 1.9 indicates a low severity impact, and the vulnerability is not listed in the CISA KEV catalog. With no EPSS value, the likelihood of exploitation is not quantified, but the injection bypass is local and requires privileged access to the CPUID interception components. Attackers could exploit this to evade anti‑tamper checks, potentially enabling piracy or disabling anti‑cheat measures. As no official patch is currently cited, the risk remains limited to environments where the vulnerable Denuvo version is present.

Generated by OpenCVE AI on October 3, 2026 at 00:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Denuvo Anti‑Tamper module to the latest version released after 2026‑03‑04, which contains the CPUID interception fix.
  • Restrict or disable privileged access to CPUID interception drivers (SimpleSvm.sys, hyperkd.sys, hyperhv.dll) through device access controls or system hardening to reduce the chance of bypass.
  • Monitor Irdeto advisories and security bulletins for any updates or workarounds regarding hypervisor detection bypass.

Generated by OpenCVE AI on October 3, 2026 at 00:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 00:45:00 +0000

Type Values Removed Values Added
Title Denuvo Anti‑Tamper Hypervisor Detection Bypass via CPUID Interception

Fri, 02 Oct 2026 23:15:00 +0000

Type Values Removed Values Added
Description Denuvo Anti-Tamper through 2026-03-04 allows bypass of a hypervisor presence check via CPUID interception (SimpleSvm.sys on AMD; hyperkd.sys and hyperhv.dll on Intel).
Weaknesses CWE-348
References
Metrics cvssV3_1

{'score': 1.9, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-02T22:59:56.650Z

Reserved: 2026-10-02T22:59:55.746Z

Link: CVE-2026-105051

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T23:16:58.247

Modified: 2026-10-02T23:16:58.247

Link: CVE-2026-105051

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T00:30:19Z

Weaknesses
  • CWE-348

    Use of Less Trusted Source