Impact
This vulnerability in AMD Zen processors permits an authorized local attacker to read arbitrary memory contents, potentially revealing sensitive data. The CVE record assigns CWE‑1303 to this flaw, which indicates an access control issue that allows unauthorized data disclosure at the local level. The attacker must already have authorized access or privilege on the target system to trigger the disclosure.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; Windows Server 2012 R2, 2016, 2019, 2022 and 2025 are listed by Microsoft as vulnerable. These products cover 32‑bit, 64‑bit, and ARM64 architectures as noted in the CPE registry.
Risk and Exploitability
The CVSS score is 5.6 and the EPSS score is below 1 %, indicating that exploitation is currently unlikely. The vulnerability is not present in the CISA KEV catalogue. The attack vector is local; an attacker must already have authorized access or sufficient local privileges to read memory, limiting the threat to compromised machines or users with elevated rights. While no public exploit has been reported, the confidentiality of user data on infected systems could be partially compromised.
OpenCVE Enrichment