Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Endpoint Security

New ‘StackWarp’ Attack Threatens Confidential VMs on AMD Processors

Researchers have disclosed technical details on a new AMD processor attack that allows remote code execution inside confidential VMs.

AMD CPU vulnerability

A team of researchers from the CISPA Helmholtz Center for Information Security in Germany has disclosed the details of a new hardware vulnerability affecting AMD processors. 

Dubbed StackWarp, the issue has been found to impact AMD Zen 1 through Zen 5 processors, enabling an attacker to hack confidential virtual machines (CVMs).  

The researchers described StackWarp as a software-based architectural attack that “exploits a synchronization failure in the stack engine that manages stack pointer updates in the CPU frontend”.

Exploitation of the vulnerability enables a malicious VM host to manipulate the guest VM’s stack pointer to hijack control and data flows, enabling remote code execution and privilege escalation inside CVMs.

The CISPA researchers have demonstrated the impact of the attack in several attack scenarios, including reconstructing an RSA-2048 private key, circumventing OpenSSH password authentication, bypassing Sudo’s password prompt, and achieving kernel-mode code execution in a VM.

Conducting these types of attacks typically requires privileged control over the host server running the CVMs. Attacks could be launched by rogue employees of a cloud provider or a sophisticated threat actor that has gained access to the provider’s systems. 

Advertisement. Scroll to continue reading.

While the chances of such an attack being conducted in the wild are small, the StackWarp attack shows that AMD’s SEV-SNP, which is designed to encrypt VM memory to protect it even against the cloud provider, can be undermined without the attacker ever seeing decrypted memory. 

“These findings demonstrate that CVM execution integrity—the very defense SEV-SNP aims to offer—can be effectively broken: Confidential keys and passwords can be stolen, attackers can impersonate legitimate users or gain persistent control of the system, and isolation between guest VMs and the host or other VMs can no longer be relied upon,” the researchers said.

AMD has been informed about the vulnerability and published an advisory on Thursday. The chip giant has assigned the flaw a low severity rating and told SecurityWeek that patches have been available for the impacted server (EPYC) products since July 2025. 

The CVE identifier CVE-2025-29943 has been assigned to the StackWarp vulnerability. 

The researchers have set up a dedicated website for StackWarp, and a paper with the full technical details has also been published. Videos showing the attack in action are also available.

Related: AMD Patches CPU Vulnerability That Could Break Confidential Computing Protections

Related: Chipmaker Patch Tuesday: Intel, AMD, Arm Respond to New CPU Attacks

Related: Intel, AMD Processors Affected by PCIe Vulnerabilities

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Stephen Garcia has been named Chief Information Security Officer at BreachRx.

Kasper Lindgaard has been appointed Vice President of Security Strategy at CoreView.

Chaim Mazal has been named Chief Information Security Officer at GitLab.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.