CVE-2025-54518
Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instruction
CVSS
7.0
High
EPSS
0.3%
p17
KEV
—
Exploit Today
5
0-100
Published: May 15, 2026 · Last modified: Jul 15, 2026 · CWE-1189 · CWE-1220
0.3%EPSS · 30 days0.3%
2026-06-302026-07-21
Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructions executed at a different privilege level, potentially resulting in privilege escalation.
- www.amd.comhttps://www.amd.com/en/resources/product-security/bulletin/AMD-SB-7052.html
- www.openwall.comhttp://www.openwall.com/lists/oss-security/2026/05/12/15
- xenbits.xen.orghttp://xenbits.xen.org/xsa/advisory-490.html
- access.redhat.comhttps://access.redhat.com/security/cve/CVE-2025-54518
- bugzilla.redhat.comhttps://bugzilla.redhat.com/show_bug.cgi?id=2477784
- security.access.redhat.comhttps://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-54518.json
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-505028.0 HIG45.4%
——14Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network.7dCVE-2026-504057.8 HIG11.9%
——4Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate privileges locally.2dCVE-2026-561557.8 HIG30.3%
KEV—59Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability 7dCVE-2026-550067.8 HIG12.5%
——4Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.8dCVE-2026-491707.8 HIG84.9%
——25Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.6dCVE-2026-485817.8 HIG12.4%
——4Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally.8d