CVE-2025-61972CWE-1233

Missing lock bit protection for NBIO registers could allow a local admin-privileged attacker to gain arbitrary System Management Network (SMN) access…

High · published May 13, 2026

CVSS v4.0
8.5
EPSS
0%
Percentile
2.9
In the wild
Unconfirmed
What it is

Missing lock bit protection for NBIO registers could allow a local admin-privileged attacker to gain arbitrary System Management Network (SMN) access, potentially resulting in arbitrary code execution in AMD Secure Processor (ASP) and loss of the SEV-SNP guest's confidentiality and integrity.

The record
Technical detail
CVSS v4.0
8.5 · HIGH
Vector
CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
EPSS
0.00130 · 2.9th percentile
Weakness
CWE-1233 · Security-Sensitive Hardware Controls with Missing Lock Bit Protection
Published
2026-05-13T03:03Z
EPSS history
Timeline
  • 13 MAY 03:03Z
    Missing lock bit protection for NBIO registers could allow a local admin-privileged attacker to gain arbitrary System Management Network (SMN) access…
    cvelistv5