CVE-2025-35979
📛 CVE Title
CVE-2025-35979
Description
Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution for some Intel(R) Processors within VMX non-root (guest) operation may allow an information disclosure. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (none) and availability (none) impacts.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- intel
- CVSS severity
- MEDIUM
- CVSS score
- 6.8 / 10
- CVSS vector
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N- Effective score
- 6.8 / 10 MEDIUM source: CNA overview
- CWE(s)
-
CWE-1423 - Reserved
- 2025-04-15
- Published
- 2026-05-12 18:35 UTC
- Last updated
- 2026-05-12 19:06 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2025/35xxx/CVE-2025-35979.json
- Linked Threat
- CVE-2025-35979 — CVE-2025-35979
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2025-209791 - Assigner
- intel
- Published
- May 12, 2026, 4:35:09 PM
- Updated
- May 12, 2026, 5:06:38 PM
- EUVD base score (CVSS 4.0)
-
6.8 / 10
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N - EUVD-reported EPSS
- 0.0200
- Vendors
- n/a
- Products
-
Intel(R) Processors (See references)
ENISA description: Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution for some Intel(R) Processors within VMX non-root (guest) operation may allow an information disclosure. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (none) and availability (none) impacts.
EUVD references (1)
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| n/a | Intel(R) Processors |
See references (affected)
|
— |
Vendor references (1)
References embedded in the original CVE record by the assigning CNA.
MITRE references (1) cveawg.mitre.org
Pulled from MITRE's CVE Services API by the 🛰 Backfill from MITRE button.
Web references (7)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- https://attackerkb.com/topics/CVE-2025-35979 rapid7:attackerkb.com
- https://security.alpinelinux.org/vuln/CVE-2025-35979 rapid7:security.alpinelinux.org
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-209791 rapid7:euvd.enisa.europa.eu
- http://cwe.mitre.org/data/definitions/1423.html rapid7:cwe.mitre.org
- https://www.first.org/epss/ tenable:www.first.org
- https://nvd.nist.gov/vuln/detail/CVE-2025-35979 tenable:nvd.nist.gov
- https://www.cve.org/CVERecord?id=CVE-2025-35979 tenable:www.cve.org
Remediations (13)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:gbhackers.com
Microsoft has released its September 2025 Patch Tuesday update, addressing a total of 81 security vulnerabilities across its product portfolio.
2026-05-23 20:57 UTC -
web:krebsonsecurity.com
Microsoft Corp. today issued security updates to fix more than 80 vulnerabilities in its Windows operating systems and software. There are no known "zero-day" or actively exploited vulnerabilities ...
2026-05-23 20:57 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-05-23 20:57 UTC -
web:www.bleepingcomputer.com
Today is Microsoft's September 2025 Patch Tuesday, which includes security updates for 81 flaws, including two publicly disclosed zero-day vulnerabilities.
2026-05-23 20:57 UTC -
web:www.crowdstrike.com
Microsoft has released security updates for 107 vulnerabilities, including one publicly disclosed zero-day and 13 critical, in its August 2025 Patch Tuesday rollout.
2026-05-23 20:57 UTC -
web:www.lansweeper.com
Which vulnerabilities, issues, and other things did Microsoft update? Discover what's new using Lansweeper's Patch Tuesday August 2025 summary.
2026-05-23 20:57 UTC -
web:www.neowin.net
Microsoft has released Patch Tuesday updates for Windows 11 (KB5063878, KB5063875) for August 2025 . Here's what's included.
2026-05-23 20:57 UTC -
web:www.oracle.com
This Critical Patch Update contains 374 new security patches across the product families listed below. Please note that an MOS note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at October 2025 Critical Patch Update: Executive Summary and Analysis.
2026-05-23 20:57 UTC -
web:www.rapid7.com
Microsoft is addressing 176 vulnerabilities this September 2025 Patch Tuesday, which is a lot. This includes a zero-day denial of service vulnerability in SQL Server.
2026-05-23 20:57 UTC -
web:www.tenable.com
Microsoft patched 107 CVEs in its August 2025 Patch Tuesday release, with 13 rated critical, 91 rated as important, one rated as moderate and one rated as low. This month's update includes patches for:
2026-05-23 20:57 UTC -
web:blog.talosintelligence.com
Microsoft Patch Tuesday for October 2025 — Snort rules and prominent vulnerabilities Microsoft has released its monthly security update for October 2025 , addressing 175 Microsoft CVEs and 21 non-Microsoft CVEs . Among these, 17 vulnerabilities are considered critical and 11 are flagged as important and considered more likely to be exploited.
2026-05-26 02:53 UTC -
web:gbhackers.com
Microsoft has rolled out its August 2025 Patch Tuesday fixes, addressing a total of 107 vulnerabilities across its ecosystem.
2026-05-26 02:53 UTC -
web:support.esri.com
This security patch addresses multiple security vulnerabilities found in ArcGIS Server. Esri recommends that all customers using ArcGIS Server 11.5, 11.4, 11.3, 11.1 and 10.9.1 apply this patch .
2026-05-26 02:53 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2025-35979.json.
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2025-35979",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-05-12T16:59:25.435200Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-05-12T17:06:38.320Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Intel(R) Processors",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "See references"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution for some Intel(R) Processors within VMX non-root (guest) operation may allow an information disclosure. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (none) and availability (none) impacts."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "HIGH",
"attackRequirements": "PRESENT",
"attackVector": "LOCAL",
"baseScore": 6.8,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "HIGH",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "NONE"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "Information Disclosure",
"lang": "en"
},
{
"cweId": "CWE-1423",
"description": "Exposure of Sensitive Information caused by Shared Microarchitectural Predictor State that Influences Transient Execution",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-05-12T16:35:09.865Z",
"orgId": "6dda929c-bb53-4a77-a76d-48e79601a1ce",
"shortName": "intel"
},
"references": [
{
"name": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01420.html",
"url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01420.html"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "6dda929c-bb53-4a77-a76d-48e79601a1ce",
"assignerShortName": "intel",
"cveId": "CVE-2025-35979",
"datePublished": "2026-05-12T16:35:09.865Z",
"dateReserved": "2025-04-15T21:20:16.409Z",
"dateUpdated": "2026-05-12T17:06:38.320Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}