AMD Secure Encrypted Virtualization
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 1.7%
exploitation probability
1.7%top 24% of all CVEs
observed exploitation
nono source reports it
In short
AMD's SEV/SEV-ES encryption feature lacks proper protection for nested page tables, allowing a malicious server administrator to run arbitrary code inside encrypted virtual machines. This undermines the security guarantee that VMs should be isolated from the hypervisor.
Technical detail
CVE-2020-12967 affects AMD SEV/SEV-ES by failing to protect nested page table (NPT) structures, enabling a hypervisor-level threat actor to inject code into guest VMs despite encryption. The attack requires administrator access to the hypervisor and compromises guest VM integrity and confidentiality through memory manipulation.
Summary generated and translated by AI from the official description.
The lack of nested page table protection in the AMD SEV/SEV-ES feature could potentially lead to arbitrary code execution within the guest VM if a malicious administrator has access to compromise the server hypervisor.
Affected products
AMD · SEV/SEV-ES