“The vulnerability is that the CPU uses an insecure hash function in the signature validation for microcode updates.”
AMD checks microcode signatures with an insecure hash on Zen 1 through Zen 5 server chips. An admin can load malicious microcode and break SEV-SNP. That admin is exactly who SEV-SNP exists to keep out.