CVE-2024-56161

HIGH

AMD EPYC 7001/7002/7003/9004 Series - Authenticated CPU Microcode Patch Loader Signature Verification Bypass

Title source: llm
STIX 2.1

Description

Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious CPU microcode resulting in loss of confidentiality and integrity of a confidential guest running under AMD SEV-SNP.

Scores

CVSS v3 7.2
EPSS 0.0052
EPSS Percentile 39.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-347
Status published
Products (4)
AMD/AMD EPYC™ 7001 Series NaplesPI 1.0.0.P
AMD/AMD EPYC™ 7002 Series RomePI 1.0.0.L
AMD/AMD EPYC™ 7003 Series MilanPI 1.0.0.F
AMD/AMD EPYC™ 9004 Series Genoa 1.0.0.E
Published Feb 03, 2025
Tracked Since Feb 18, 2026