Junglewise Threat Intelligence

CVE-2025-61972: AMD NBIO missing lock bit protection in registers

CVE-2025-61972 · Severity: info · CVSS 8.5 · Published 2026-05-13

Vendors: Amd.

Executive brief

A security flaw in AMD hardware components could allow a local user with administrative privileges to bypass critical security protections. This vulnerability affects the AMD Secure Processor and SEV-SNP features, which are designed to keep sensitive data and virtual machines isolated and secure. If exploited, an attacker could compromise the confidentiality and integrity of secure workloads, potentially leading to the theft of sensitive information or unauthorized control over the system's secure environment.

Technical details

This vulnerability is classified as CWE-1233 (Security-Sensitive Hardware Controls with Missing Lock Bit Protection) within the AMD Northbridge I/O (NBIO) registers. A local attacker with high privileges (Administrator/Root) can exploit the missing lock bits to gain arbitrary access to the System Management Network (SMN). This access can be leveraged to achieve arbitrary code execution within the AMD Secure Processor (ASP). Furthermore, the exploit can bypass SEV-SNP (Secure Encrypted Virtualization-Secure Nested Paging) protections, leading to a complete loss of confidentiality and integrity for guest virtual machines. AMD has released security bulletin AMD-SB-3030 to address this issue.

Affected products

  • AMD NBIO (Northbridge I/O) Firmware

Timeline

  • 2026-05-13: advisory: AMD published security bulletin AMD-SB-3030 and NVD entry created.

References

Related threats