CVE-2024-56161 is an improper signature verification vulnerability in AMD CPU ROM microcode patch loaders. This flaw allows an attacker with local administrator privileges to load malicious CPU microcode, potentially compromising the confidentiality and integrity of confidential guests running under AMD SEV-SNP. Rated 7.2 HIGH, exploitation requires high privileges and complexity, but can lead to significant data loss. There is currently no public exploit code, nor is it known to be actively exploited, though it has garnered moderate community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| AMD | AMD EPYC™ 7003 Series | Range not provided by sourceCNA affecteddefault affected | |
| AMD | AMD EPYC™ 7001 Series | Range not provided by sourceCNA affecteddefault affected | |
| AMD | AMD EPYC™ 7002 Series | Range not provided by sourceCNA affecteddefault affected | |
| AMD | AMD EPYC™ 9004 Series | Range not provided by sourceCNA affecteddefault affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
kernel: hw:amd: Vulnerability in guest VM protected by SEV when loading malicious firmware
Feb 3, 2025Vulnerability in AMD Zen-based CPUs Affecting Confidential VM Instances
Jan 1, 2024Vulnerability in AMD Zen-based CPUs affecting Confidential VM instances (CVE-2024-56161)
Vulnerability in AMD Zen-based CPUs affecting Google Cloud Confidential VMs with AMD SEV-SNP