Vulnerability Details CVE-2025-65264
The kernel driver of CPUID CPU-Z v2.17 and earlier does not validate user-supplied values passed via its IOCTL interface, allowing an attacker to access sensitive information via a crafted request.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 3.4%
CVSS Severity
CVSS v3 Score 5.5
Products affected by CVE-2025-65264
-
cpe:2.3:a:cpuid:cpu-z:1.42
-
cpe:2.3:a:cpuid:cpu-z:1.63
-
cpe:2.3:a:cpuid:cpu-z:1.64
-
cpe:2.3:a:cpuid:cpu-z:1.65
-
cpe:2.3:a:cpuid:cpu-z:1.66
-
cpe:2.3:a:cpuid:cpu-z:1.67
-
cpe:2.3:a:cpuid:cpu-z:1.68
-
cpe:2.3:a:cpuid:cpu-z:1.69
-
cpe:2.3:a:cpuid:cpu-z:1.70
-
cpe:2.3:a:cpuid:cpu-z:1.71.1
-
cpe:2.3:a:cpuid:cpu-z:1.72.1
-
cpe:2.3:a:cpuid:cpu-z:1.73
-
cpe:2.3:a:cpuid:cpu-z:1.74
-
cpe:2.3:a:cpuid:cpu-z:1.75
-
cpe:2.3:a:cpuid:cpu-z:1.76
-
cpe:2.3:a:cpuid:cpu-z:1.77
-
cpe:2.3:a:cpuid:cpu-z:1.78
-
cpe:2.3:a:cpuid:cpu-z:1.79
-
cpe:2.3:a:cpuid:cpu-z:1.80
-
cpe:2.3:a:cpuid:cpu-z:1.81
-
cpe:2.3:a:cpuid:cpu-z:1.82
-
cpe:2.3:a:cpuid:cpu-z:1.83
-
cpe:2.3:a:cpuid:cpu-z:1.84
-
cpe:2.3:a:cpuid:cpu-z:1.85
-
cpe:2.3:a:cpuid:cpu-z:1.86
-
cpe:2.3:a:cpuid:cpu-z:1.87
-
cpe:2.3:a:cpuid:cpu-z:1.88
-
cpe:2.3:a:cpuid:cpu-z:1.89
-
cpe:2.3:a:cpuid:cpu-z:1.90
-
cpe:2.3:a:cpuid:cpu-z:1.91
-
cpe:2.3:a:cpuid:cpu-z:1.92