CVE Feed

    Dashboard / CVE / CVE-2025-51060

    CVE-2025-51060

    An issue was discovered in CPUID cpuz.sys 1.0.5.4. An attacker can use DeviceIoControl with the unvalidated parameters 0x9C402440 and 0x9C402444 as IoControlCodes to perform RDMSR and WRMSR, respectively. Through this process, the attacker can modify MSR_LSTAR and hook KiSystemCall64. Afterward, using Return-Oriented Programming (ROP), the attacker can manipulate the stack with pre-prepared gadgets, disable the SMAP flag in the CR4 register, and execute a user-mode syscall handler in the kernel context. It has not been confirmed whether this works on 32-bit Windows, but it functions on 64-bit Windows if the core isolation feature is either absent or disabled.

    Published:Aug 5, 2025
    Last Modified:Oct 9, 2025
    EPS:Aug 5, 2025
    EPSS Score:0.00038
    CVSS Score:6.5

    Affected Products

    Vendor
    Cpuid
    Product
    Cpu-z
    Vendor
    Cpuid
    Product
    Cpuz.sys
    Vendor
    Microsoft
    Product
    Windows

    Common Weakness Enumeration

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High