Search/CVE-2025-48514
CVE

CVE-2025-48514

Insufficient Granularity of Access Control in SEV firmware can allow a privileged attacker to create a SEV-ES Guest to attack SNP guest, potentially resulting in a loss of confidentiality.

CVSS v3.1
EPSS
0.14%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
EPSS Trend
Aug 16, 2026Sep 10, 2026
0.01pp
0.14% → 0.14% over 2 tracked changes
Connections
1 relationships
Timeline
disclosure → media coverage
Feb 10, 2026
Disclosure — published as a CVE record. · last revised by NVD Apr 15, 2026