CVE-2024-56161

HIGH

AMD CPU ROM - Privilege Escalation

Title source: llm
STIX 2.1

Description

Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious CPU microcode resulting in loss of confidentiality and integrity of a confidential guest running under AMD SEV-SNP.

Scores

CVSS v3 7.2
EPSS 0.0008
EPSS Percentile 23.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-347
Status published
Products (4)
AMD/AMD EPYC™ 7001 Series NaplesPI 1.0.0.P
AMD/AMD EPYC™ 7002 Series RomePI 1.0.0.L
AMD/AMD EPYC™ 7003 Series MilanPI 1.0.0.F
AMD/AMD EPYC™ 9004 Series Genoa 1.0.0.E
Published Feb 03, 2025
Tracked Since Feb 18, 2026