Skip to main content
EPSS 0.3%top 80%

CVE-2025-51060: n/a

0
Medium
VulnerabilityCVE-2025-51060cvecve-2025-51060
Published: 08/05/2025 (08/05/2025, 00:00:00 UTC)
Source: CVE Database V5

Description

An issue was discovered in CPUID cpuz.sys 1.0.5.4. An attacker can use DeviceIoControl with the unvalidated parameters 0x9C402440 and 0x9C402444 as IoControlCodes to perform RDMSR and WRMSR, respectively. Through this process, the attacker can modify MSR_LSTAR and hook KiSystemCall64. Afterward, using Return-Oriented Programming (ROP), the attacker can manipulate the stack with pre-prepared gadgets, disable the SMAP flag in the CR4 register, and execute a user-mode syscall handler in the kernel context. It has not been confirmed whether this works on 32-bit Windows, but it functions on 64-bit Windows if the core isolation feature is either absent or disabled.

CVSS v3.1

Score 6.5medium

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Affected software

Affected versions
=1.0.5.4

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/05/2026, 21:19:18 UTC

Technical Analysis

The vulnerability in CPUID cpuz.sys 1.0.5.4 arises from improper validation of DeviceIoControl parameters 0x9C402440 and 0x9C402444, which correspond to IOCTL codes for RDMSR and WRMSR instructions. An attacker can leverage these to modify the MSR_LSTAR register, hooking the KiSystemCall64 system call handler. Using Return-Oriented Programming (ROP), the attacker can manipulate the stack, disable the SMAP flag in the CR4 register, and execute user-mode syscall handlers with kernel privileges. This exploit is confirmed on 64-bit Windows systems where core isolation is disabled or absent; its applicability on 32-bit Windows is unconfirmed.

Potential Impact

Successful exploitation allows an attacker to escalate privileges by executing arbitrary code in kernel context through system call hooking and manipulation of CPU registers. This can lead to unauthorized control over the affected system with potential confidentiality and integrity impacts. The vulnerability does not impact availability and requires no privileges or user interaction to exploit.

Mitigation Recommendations

No official patch or fix is currently available for this vulnerability. Users should verify if core isolation features are enabled on their 64-bit Windows systems, as the exploit requires core isolation to be absent or disabled. Monitor vendor advisories for updates regarding patches or mitigations. Until a fix is released, restricting access to the vulnerable driver and minimizing exposure to untrusted code execution paths may reduce risk.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.1
Assigner Short Name
mitre
Date Reserved
2025-06-16T00:00:00.000Z
State
PUBLISHED

Threat ID: 68924ac9ad5a09ad00eadd63

Added to database: 08/05/2025, 18:17:45 UTC

Last enriched: 07/05/2026, 21:19:18 UTC

Last updated: 09/10/2026, 19:36:50 UTC

Views: 182

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses