Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-56161

24
FAUCET Score

CVE-2024-56161 is an improper signature verification vulnerability in AMD CPU ROM microcode patch loaders. This flaw allows an attacker with local administrator privileges to load malicious CPU microcode, potentially compromising the confidentiality and integrity of confidential guests running under AMD SEV-SNP. Rated 7.2 HIGH, exploitation requires high privileges and complexity, but can lead to significant data loss. There is currently no public exploit code, nor is it known to be actively exploited, though it has garnered moderate community and media attention.

Impacted Technologies

VendorProductVersion(s)CPE
AMDAMD EPYC™ 7003 Series
Range not provided by sourceCNA affecteddefault affected
AMDAMD EPYC™ 7001 Series
Range not provided by sourceCNA affecteddefault affected
AMDAMD EPYC™ 7002 Series
Range not provided by sourceCNA affecteddefault affected
AMDAMD EPYC™ 9004 Series
Range not provided by sourceCNA affecteddefault affected

CVSS Data

CVSS version used by this source: 3.1

7.2HIGH

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
0.8
Impact Score
5.8
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.52%
Probability of exploitation in next 30 days
EPSS Percentile
41.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0052 is in the 89th percentile among its peer group of 160 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

chainsafepatch availablevia llm_extracted
Fixed in: SNP TCB SVN: 0x18 0d24, psp_bootloader_version: 4, snp_firmware_version: 24 (0x18), microcode_version: 219
View patch
coollabspatch availablevia llm_extracted
Fixed in: SNP TCB SVN: 0x18 0d24, psp_bootloader_version: 4, snp_firmware_version: 24 (0x18), microcode_version: 219
View patch
falcopatch availablevia llm_extracted
Fixed in: SNP TCB SVN: 0x18 0d24, psp_bootloader_version: 4, snp_firmware_version: 24 (0x18), microcode_version: 219
View patch

Vendor Advisories (4)

redhatCVE-2024-56161Important

kernel: hw:amd: Vulnerability in guest VM protected by SEV when loading malicious firmware

Feb 3, 2025
chainsafellm-chainsafe-8b25fa554e9da5daHIGH

Vulnerability in AMD Zen-based CPUs Affecting Confidential VM Instances

Jan 1, 2024
coollabsllm-coollabs-e03814ba519a0ee5HIGH

Vulnerability in AMD Zen-based CPUs affecting Confidential VM instances (CVE-2024-56161)

falcollm-falco-72e97082a47f2d90HIGH

Vulnerability in AMD Zen-based CPUs affecting Google Cloud Confidential VMs with AMD SEV-SNP

References

lists.debian.org / debian-lts-announce/2025/03/msg00024.html
amd.com / en/resources/product-security/bulletin/amd-sb-7033.html
openwall.com / lists/oss-security/2025/02/04/1
openwall.com / lists/oss-security/2025/03/06/2
amd.com / en/resources/product-security/bulletin/amd-sb-3019.html