← back
CVE-2025-29948mediumCWE-1260

CVE-2025-29948

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 5.9epss 0.1%
exploitation probability
0.1%top 96% of all CVEs
observed exploitation
nono source reports it
In short

A flaw in AMD's SEV secure virtualization firmware allows a malicious hypervisor to bypass memory protections, putting guest data integrity at risk. This affects systems relying on AMD's secure encryption features to protect sensitive workloads.

Technical detail

Improper access control in AMD SEV firmware enables a hypervisor-level attacker to circumvent Reverse Map Table (RMP) protections, compromising SEV-SNP guest memory isolation. The vulnerability requires hypervisor-level access and could result in unauthorized guest memory modification, violating the security guarantees of encrypted virtualization.

Summary generated and translated by AI from the official description.
Improper access control in AMD Secure Encrypted Virtualization (SEV) firmware could allow a malicious hypervisor to bypass RMP protections, potentially resulting in a loss of SEV-SNP guest memory integrity.
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N