CVE-2024-36350

Advisory lineage Upstream: 0 Downstream: 54
Deferred
Published: 08 Jul 2025, 16:56
Last modified:04 Nov 2025, 21:08

Vulnerability Summary

Overall Risk (default)
low
22/100
CVSS Score
5.6 MEDIUM
v3.1 (cve.org)
EPSS Score
0.03% LOW
0% probability +0.02%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

08 Jul 2025, 16:56
Published
Vulnerability first disclosed
04 Nov 2025, 21:08
Last Modified
Vulnerability information updated

Description

A transient execution vulnerability in some AMD processors may allow an attacker to infer data from previous stores, potentially resulting in the leakage of privileged information.

CVSS Metrics

  • v3.1MEDIUMScore: 5.6CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N

EPSS Trends

Current EPSS score: 0.03% Percentile: 10%

Techniques & Countermeasures

  • CWE-1421Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution

    A processor event may allow transient operations to access architecturally restricted data (for example, in another address space) in a shared microarchitectural structure (for example, a CPU cache), potentially exposing the data over a covert channel.

References (5)