Improper Access Control in AMD SEV-SNP Product by AMD
CVE-2025-0033
6MEDIUM
What is CVE-2025-0033?
An improper access control vulnerability in AMD's SEV-SNP technology could enable an attacker with administrative privileges to write to the Read Memory Protection (RMP) during the Secure Nested Paging (SNP) initialization process. This could potentially compromise the integrity of the SEV-SNP guest memory, allowing unauthorized manipulation of memory resources.
Affected Version(s)
AMD EPYC™ 7003 Series Processors (formerly codenamed "Milan") MilanPI 1.0.0.H
AMD EPYC™ 9005 Series Processors (formerly codenamed "Turin") TurinPI 1.0.0.6
News Articles

RMPocalypse: Single 8-Byte Write Shatters AMD’s SEV-SNP Confidential Computing
AMD patches CVE-2025-0033 “RMPocalypse,” a flaw allowing full SEV-SNP VM compromise via RMP overwrite.
1 week ago