Impact
The vulnerability originates from a flaw in AMD Zen CPUs that allows an authorized local user to read sensitive data on the host system. This flaw is categorized as CWE‑1303, an information exposure by a local process. An attacker who already has local, authorized access can therefore expose confidential information; no elevated privileges or remote access are required.
Affected Systems
Microsoft Windows 10 build 1607, 1809, 21H2, 22H2 and Windows 11 builds 23H2, 24H2, 25H2, 26H1, as well as Windows Server 2012 R2, 2016, 2019, 2022 and 2025 are vulnerable when running on AMD Zen processors. These versions are catalogued in the Microsoft advisory and correspond to the provided CPE strings.
Risk and Exploitability
The CVSS base score of 5.6 indicates moderate risk. An EPSS score of less than 1 % suggests a very low likelihood of exploitation at this time. The attack requires local and authorized access, limiting the threat to users with legitimate privileges on the machine. Because the issue is not included in the CISA KEV catalog, no widespread exploitation campaigns have been reported. Nonetheless, the potential to leak user or system data warrants a prompt patch.
OpenCVE Enrichment