CVE-2025-36357: IBM Planning Analytics Local Directory Traversal
AMD: CVE-2025-36357 Transient Scheduler Attack in L1 Data Queue
Other sources
IBM Planning Analytics Local 2.1.0 through 2.1.14 could allow a remote authenticated user to traverse directories on the system. An attacker could send a specially crafted URL request containing absolute path sequences to view, read, or write arbitrary files on the system.
— MITRE
The vulnerability assigned to this CVE is in certain processor models offered by AMD. The mitigation for this vulnerability requires a Windows update. This CVE is being documented in the Security Update Guide to announce that the latest builds of Windows enable the mitigation and provide protection against the vulnerability. Please see the following for more information:
AMD-SB-7029
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36357?
CVE-2025-36357 is considered to have a high severity due to the potential impact on certain AMD processor models.
How do I fix CVE-2025-36357?
To fix CVE-2025-36357, you need to install the latest Windows update that provides the necessary mitigation.
Which operating systems are affected by CVE-2025-36357?
CVE-2025-36357 affects various versions of Microsoft Windows, including Windows 10, Windows 11, and Windows Server 2016 and later.
Are AMD processors the only ones affected by CVE-2025-36357?
Yes, the vulnerability specifically affects certain AMD processor models.
What steps should I take to mitigate CVE-2025-36357?
You should ensure that your Windows operating system is updated to the latest version to activate the mitigation against CVE-2025-36357.