Source · Tier A · Peer-reviewed

RMPocalypse: How a Catch-22 Breaks AMD SEV-SNP

B. Schlüter, S. Shinde. 2025. 2025 ACM SIGSAC Conference on Computer and Communications Security (CCS '25).

Linkhttps://rmpocalypse.github.io/
DOI10.1145/3719027.3765233
VersionRead the authors' site and the paper PDF linked from it (https://rmpocalypse.github.io/rmpocalypse-CCS2025.pdf) on 2026-09-24. The DOI and venue are from the ACM reference block printed in the PDF.
Accessed2026-09-24
NoteIndependent attack paper (ETH Zurich). A malicious hypervisor corrupts AMD's Reverse Map Table during SEV-SNP initialisation, with no physical access. Confirmed on Zen 3, Zen 4 and Zen 5 processors. Demonstrates enabling debug on production confidential VMs, faking attestation, register-state replay and code injection. AMD assigned CVE-2025-0033; AMD's bulletin is S-1213.

Cited by