CVE-2019-7245: Techpowerup GPU-Z
High severity, CVSS 7.2. EPSS: 2.5% chance of exploitation in the next 30 days.
An issue was discovered in GPU-Z.sys in TechPowerUp GPU-Z before 2.23.0. The vulnerable driver exposes a wrmsr instruction via an IOCTL and does not properly filter the Model Specific Register (MSR). Allowing arbitrary MSR writes can lead to Ring-0 code execution and escalation of privileges.
Affected products
- Techpowerup GPU-Z: before 2.23.0 (fixed in 2.23.0)
Published 2020-03-25. Last modified 2026-06-17.