CVE-2025-5324 Details
Description
A vulnerability, which was classified as problematic, was found in TechPowerUp GPU-Z 2.23.0. Affected is the function sub_140001880 in the library GPU-Z.sys of the component 0x8000645C IOCTL Handler. The manipulation leads to memory leak. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
A kernel memory leak vulnerability has been identified in TechPowerUp GPU-Z versions prior to 2.23.0. The issue resides in the GPU-Z.sys driver, specifically within the 0x8000645C IOCTL handler. This vulnerability allows low-privileged users to leak kernel memory by sending crafted IOCTL requests, potentially exposing sensitive kernel-space data. The vulnerability can be exploited locally.
Users are advised to update to TechPowerUp GPU-Z version 2.23.0 or later. For developers, it is recommended to implement strict validation and sanitization of IOCTL control codes in the GPU-Z.sys driver, validate and restrict physical memory mappings to non-sensitive regions, and require elevated privileges for critical IOCTL operations.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 29, 2025CISA-ADP
Assessed May 29, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Aiyakami/CVE-1/issues/3 | [email protected] | ExploitIssue TrackingTechnical Description |
| https://github.com/Aiyakami/CVE-1/tree/main/test1 | [email protected] | Source Code |
| https://vuldb.com/?ctiid.310494 | [email protected] | AdvisoryContent Wall |
| https://vuldb.com/?id.310494 | [email protected] | AdvisoryContent Wall |
| https://vuldb.com/?submit.580513 | [email protected] | Technical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-401 | Missing Release of Memory after Effective Lifetime | [email protected] |
| CWE-404 | Improper Resource Shutdown or Release | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| TechPowerUp GPU-Z | 2.23.0 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 29, 2025 | New CVE Received | [email protected] |
Volerion