Microsoft disclosed and patched CVE-2023-20588, an AMD processor information disclosure vulnerability known as AMD Speculative Leaks, after including mitigations in its December 2023 security updates. The flaw affects multiple AMD CPU families, including EPYC, Athlon, and Ryzen 3000-series processors, and stems from divide-by-zero behavior that can cause the processor to transiently return random or stale data during speculative execution.
The issue requires local access to exploit, but it was treated as a high-severity risk because sensitive data could be exposed from affected systems. Microsoft and CSIRT.SK said the vulnerability was identified by researchers from Microsoft Azure Research and Vrije Universiteit Amsterdam, and they urged organizations to apply Windows updates promptly. Guidance also advised developers to avoid using privileged data in divide-by-zero operations and to follow secure coding practices to reduce exposure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
According to CSIRT.SK, Microsoft's December 2023 Patch Tuesday included fixes for CVE-2023-20588, a zero-day affecting AMD processors. Microsoft also published a Security Update Guide advisory for the issue.
CSIRT.SK states that CVE-2023-20588 was discovered by researchers from Microsoft Azure Research and Vrije Universiteit Amsterdam. The flaw is an information disclosure issue in AMD processors related to divide-by-zero behavior that can return transient or random data.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.