CVE-2024-21980 is a vulnerability in AMD Secure Nested Paging (SNP) firmware where improper restriction of write operations allows a malicious hypervisor to overwrite a guest's memory or UMC seed. This flaw undermines the isolation guarantees provided by SNP, potentially exposing guest VMs to attacks from a compromised or malicious hypervisor.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a proof-of-concept (PoC) exploit for a vulnerability in AMD SEV firmware (tested on version 1.55.16) that allows decryption of arbitrary memory from a decommissioned SEV-SNP guest. The exploit leverages a flaw in the handling of the SEV_MCMD_ID_ATTESTATION command, which lacks proper buffer enforcement, allowing memory corruption in RMP-covered areas. The repository includes: - A set of Linux kernel patches (linux-patches/) that modify KVM and SEV-related code to facilitate the attack, such as allowing use of specific physical addresses for guest context pages, exposing new ioctl commands for debugging/decryption, and logging secret page locations. - A Rust-based PoC tool (src/) that interacts with the patched kernel, creates SEV-SNP guests, triggers the vulnerability, and decrypts memory pages by reusing a corrupted UMC key seed. - The exploit requires a specific system configuration (large RMP area, patched kernel, and control over guest lifecycle) and is primarily a local attack vector, requiring root or equivalent privileges on the host. The main entry point is src/main.rs, which orchestrates the attack steps. The exploit is not weaponized but provides a clear demonstration of the vulnerability and its impact. No network endpoints are involved; the attack is performed via direct device file access (/dev/kvm, /dev/sev) and kernel modifications.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.