PT-2025-41795 · Amd · Zen 3 +4
Published
2025-10-13
·
Updated
2025-10-14
·
CVE-2025-0033
CVSS v3.1
6.0
6.0
Medium
Base vector | Vector | AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
AMD EPYC and EPYC Embedded series processors versions prior to BIOS updates from OEM partners
AMD EPYC processors using Secure Encrypted Virtualization – Secure Nested Paging (SEV-SNP) (affected versions not specified)
Description
A critical issue, dubbed RMPocalypse (CVE-2025-0033), has been identified in AMD's Secure Encrypted Virtualization with Secure Nested Paging (SEV-SNP) technology. This flaw stems from a race condition during the initialization of the Reverse Map Table (RMP) within the AMD Secure Processor (ASP). The RMP is designed to protect guest page mappings from unauthorized modification by the hypervisor. However, a vulnerability exists during RMP initialization, allowing a malicious or compromised hypervisor to overwrite RMP entries before they are locked. This single 8-byte write to the RMP table during initialization compromises all SEV-SNP security guarantees.
The vulnerability allows a malicious hypervisor to corrupt the RMP, enabling complete compromise of confidential virtual machine integrity and confidentiality. Attackers can potentially exfiltrate all encrypted data within confidential VMs, execute arbitrary code, and achieve persistence across VM operations. The issue affects processors from the Zen 3, Zen 4, and Zen 5 architectures. The vulnerability does not expose plaintext data or secrets directly, but requires privileged control of the hypervisor to exploit. The RMP is a large data structure (up to 16 GB) stored in DRAM, and its correct initialization is crucial for the security of SEV-SNP.
Recommendations
Apply BIOS/firmware updates from hardware manufacturers.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
dbugs@ptsecurity.com
Weakness Enumeration
Related Identifiers
CVE-2025-0033
Affected Products
Amd Processors
Epyc
Sev-Snp
Zen 3
Zen 5
References · 17
- https://nvd.nist.gov/vuln/detail/CVE-2025-0033 · Security Note
- https://twitter.com/fridaysecurity/status/1977894551252557920 · Twitter Post
- https://twitter.com/TheHackersNews/status/1978066223284748492 · Twitter Post
- https://twitter.com/cytexsmb/status/1978155127866323349 · Twitter Post
- https://reddit.com/r/pwnhub/comments/1o5mo65/new_rmpocalypse_attack_threatens_amd_sevsnp_and · Reddit Post
- https://t.me/pentestingnews/69520 · Telegram Post
- https://twitter.com/Action1corp/status/1978153782891696533 · Twitter Post
- https://t.me/thehackernews/7714 · Telegram Post
- https://twitter.com/CVEnew/status/1978118127402782971 · Twitter Post
- https://reddit.com/r/Action1/comments/1o6mazp/patch_tuesday_october_2025 · Reddit Post
- https://twitter.com/VeryVillanous/status/1978193979486163232 · Twitter Post
- https://amd.com/en/resources/product-security/bulletin/AMD-SB-3020.html · Note
- https://t.me/true_secator/7523 · Telegram Post
- https://t.me/msrcreports/2185 · Telegram Post
- https://twitter.com/zeeshankghouri/status/1977933758356398121 · Twitter Post