CVE-2025-51060: n/a
An issue was discovered in CPUID cpuz.sys 1.0.5.4. An attacker can use DeviceIoControl with the unvalidated parameters 0x9C402440 and 0x9C402444 as IoControlCodes to perform RDMSR and WRMSR, respectively. Through this process, the attacker can modify MSR_LSTAR and hook KiSystemCall64. Afterward, using Return-Oriented Programming (ROP), the attacker can manipulate the stack with pre-prepared gadgets, disable the SMAP flag in the CR4 register, and execute a user-mode syscall handler in the kernel context. It has not been confirmed whether this works on 32-bit Windows, but it functions on 64-bit Windows if the core isolation feature is either absent or disabled.
AI Analysis
Technical Summary
The vulnerability in CPUID cpuz.sys 1.0.5.4 arises from improper validation of DeviceIoControl parameters 0x9C402440 and 0x9C402444, which correspond to IOCTL codes for RDMSR and WRMSR instructions. An attacker can leverage these to modify the MSR_LSTAR register, hooking the KiSystemCall64 system call handler. Using Return-Oriented Programming (ROP), the attacker can manipulate the stack, disable the SMAP flag in the CR4 register, and execute user-mode syscall handlers with kernel privileges. This exploit is confirmed on 64-bit Windows systems where core isolation is disabled or absent; its applicability on 32-bit Windows is unconfirmed.
Potential Impact
Successful exploitation allows an attacker to escalate privileges by executing arbitrary code in kernel context through system call hooking and manipulation of CPU registers. This can lead to unauthorized control over the affected system with potential confidentiality and integrity impacts. The vulnerability does not impact availability and requires no privileges or user interaction to exploit.
Mitigation Recommendations
No official patch or fix is currently available for this vulnerability. Users should verify if core isolation features are enabled on their 64-bit Windows systems, as the exploit requires core isolation to be absent or disabled. Monitor vendor advisories for updates regarding patches or mitigations. Until a fix is released, restricting access to the vulnerable driver and minimizing exposure to untrusted code execution paths may reduce risk.
CVE-2025-51060: n/a
Description
An issue was discovered in CPUID cpuz.sys 1.0.5.4. An attacker can use DeviceIoControl with the unvalidated parameters 0x9C402440 and 0x9C402444 as IoControlCodes to perform RDMSR and WRMSR, respectively. Through this process, the attacker can modify MSR_LSTAR and hook KiSystemCall64. Afterward, using Return-Oriented Programming (ROP), the attacker can manipulate the stack with pre-prepared gadgets, disable the SMAP flag in the CR4 register, and execute a user-mode syscall handler in the kernel context. It has not been confirmed whether this works on 32-bit Windows, but it functions on 64-bit Windows if the core isolation feature is either absent or disabled.
CVSS v3.1
Score 6.5medium
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in CPUID cpuz.sys 1.0.5.4 arises from improper validation of DeviceIoControl parameters 0x9C402440 and 0x9C402444, which correspond to IOCTL codes for RDMSR and WRMSR instructions. An attacker can leverage these to modify the MSR_LSTAR register, hooking the KiSystemCall64 system call handler. Using Return-Oriented Programming (ROP), the attacker can manipulate the stack, disable the SMAP flag in the CR4 register, and execute user-mode syscall handlers with kernel privileges. This exploit is confirmed on 64-bit Windows systems where core isolation is disabled or absent; its applicability on 32-bit Windows is unconfirmed.
Potential Impact
Successful exploitation allows an attacker to escalate privileges by executing arbitrary code in kernel context through system call hooking and manipulation of CPU registers. This can lead to unauthorized control over the affected system with potential confidentiality and integrity impacts. The vulnerability does not impact availability and requires no privileges or user interaction to exploit.
Mitigation Recommendations
No official patch or fix is currently available for this vulnerability. Users should verify if core isolation features are enabled on their 64-bit Windows systems, as the exploit requires core isolation to be absent or disabled. Monitor vendor advisories for updates regarding patches or mitigations. Until a fix is released, restricting access to the vulnerable driver and minimizing exposure to untrusted code execution paths may reduce risk.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- mitre
- Date Reserved
- 2025-06-16T00:00:00.000Z
- State
- PUBLISHED
Threat ID: 68924ac9ad5a09ad00eadd63
Added to database: 08/05/2025, 18:17:45 UTC
Last enriched: 07/05/2026, 21:19:18 UTC
Last updated: 09/10/2026, 19:36:50 UTC
Views: 182
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.