AMD SEV Firmware Downgrade via Lock Bit Modification
CVE-2025-52536 Published on February 10, 2026
Improper Prevention of Lock Bit Modification in SEV firmware could allow a privileged attacker to downgrade firmware potentially resulting in a loss of integrity.
Weakness Type
Improper Implementation of Lock Protection Registers
The product incorrectly implements register lock bit protection features such that protected controls can be programmed even after the lock has been set.
Affected Versions
AMD EPYC™ 9004 Series Processors:- Version GenoaPI 1.0.0.G is unaffected.
- Version MilanPI 1.0.0.H is unaffected.
- Version TurinPI 1.0.0.5 is unaffected.
- Version GenoaPI 1.0.0.G is unaffected.
- Version EmbMilanPI-SP3 v9 1.0.0.C is unaffected.
- Version EmbGenoaPI-SP5 1.0.0.B is unaffected.
- Version EmbTurinPI-SP5_1.0.0.1 is unaffected.
- Version EmbGenoaPI-SP5 1.0.0.B is unaffected.
- Version EmbGenoaPI-SP5 1.0.0.B is unaffected.
Exploit Probability
EPSS
0.02%
Percentile
4.20%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.