Cpuid develops system-diagnostic and hardware-information tools, most notably CPU-Z, a widely installed utility for CPU and hardware monitoring on Windows systems. The vendor's vulnerability disclosures center on access-control and input-validation weaknesses in the CPU-Z kernel driver, reflecting the privileged access required for low-level hardware interrogation. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cpuid over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-51060MEDIUM An issue was discovered in CPUID cpuz.sys 1.0.5.4. An attacker can use DeviceIoControl with the unvalidated parameters 0x9C402440 and 0x9C402444 as IoControlCodes to perform RDMSR | Aug 5, 2025 | 6.5 | 24 | NO | NO |
CVE-2017-15303HIGH In CPUID CPU-Z before 1.43, there is an arbitrary memory write that results directly in elevation of privileges, because any program running on the local machine (while CPU-Z is ru | Oct 16, 2017 | 7.8 | 24 | NO | NO |
CVE-2017-15302HIGH In CPUID CPU-Z through 1.81, there are improper access rights to a kernel-mode driver (e.g., cpuz143_x64.sys for version 1.43) that can result in information disclosure or elevatio | Oct 16, 2017 | 7.8 | 24 | NO | NO |
CVE-2025-65264MEDIUM The kernel driver of CPUID CPU-Z v2.17 and earlier does not validate user-supplied values passed via its IOCTL interface, allowing an attacker to access sensitive information via a | Jan 27, 2026 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cpuid.
Media articles that mention a CVE ID that affects a product developed by Cpuid — matched by CVE ID, not by vendor name.