Impact
Denuvo Anti‑Tamper up to 2026‑03‑04 contains a flaw that lets attackers bypass the hypervisor presence check by intercepting CPUID calls. The vulnerability stems from the CPUID interception logic in SimpleSvm.sys on AMD and hyperkd.sys and hyperhv.dll on Intel, allowing a privileged user to trick the anti‑tamper module into treating the system as if no hypervisor is running.
Affected Systems
The affected systems are installations of Irdeto’s Denuvo Anti‑Tamper, particularly versions released through 2026‑03‑04. No specific version range is listed beyond this release date.
Risk and Exploitability
The CVSS score of 1.9 indicates a low severity impact, and the vulnerability is not listed in the CISA KEV catalog. With no EPSS value, the likelihood of exploitation is not quantified, but the injection bypass is local and requires privileged access to the CPUID interception components. Attackers could exploit this to evade anti‑tamper checks, potentially enabling piracy or disabling anti‑cheat measures. As no official patch is currently cited, the risk remains limited to environments where the vulnerable Denuvo version is present.
OpenCVE Enrichment