CVE-2024-56161 Details
Description
Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious CPU microcode resulting in loss of confidentiality and integrity of a confidential guest running under AMD SEV-SNP.
A vulnerability exists in the microcode patch loader of AMD CPUs, specifically in the Zen 1-4 architectures. This issue arises from improper signature verification, allowing an attacker with local administrator privileges to load malicious microcode patches. The vulnerability could compromise the confidentiality and integrity of sensitive workloads running under AMD's Secure Encrypted Virtualization with Secure Nested Paging (SEV-SNP) feature.
Users should update to the latest microcode version provided by AMD, which addresses the signature verification flaw by implementing a more secure validation process. Additionally, an SEV firmware update may be necessary for some platforms to support SEV-SNP attestation, which could also require a BIOS update.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 3, 2025CISA-ADP
Assessed Feb 3, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://lists.debian.org/debian-lts-announce/2025/03/msg00024.html | CVE | AdvisoryMailing ListRemedy |
| https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7033.html | CVE | Broken LinkVendor |
| http://www.openwall.com/lists/oss-security/2025/02/04/1 | CVE | Mailing ListRemedy |
| http://www.openwall.com/lists/oss-security/2025/03/06/2 | CVE | Mailing ListTechnical Analysis |
| https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3019.html | [email protected] | Broken LinkVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-347 | Improper Verification of Cryptographic Signature | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| AMD Zen 1 | All versions |
CPE
Remediation
| |
| AMD Zen 2 | All versions |
CPE
Remediation
| |
| AMD Zen 3 | All versions |
CPE
Remediation
| |
| AMD Zen 4 | All versions |
CPE
Remediation
| |
| AMD EPYC 7B13 | All versions |
CPE
Remediation
| |
| AMD Ryzen 9 7940HS | All versions |
CPE
Remediation
| |
| Debian amd64-microcode | All versions |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Apr 2, 2025 | CVE Modified | CVE |
| Mar 6, 2025 | CVE Modified | CVE |
| Mar 6, 2025 | CVE Modified | CVE |
| Feb 4, 2025 | CVE Modified | CVE |
| Feb 3, 2025 | New CVE Received | [email protected] |
Volerion