CVE-2024-56161
published 2025-02-03CVE-2024-56161: Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious CPU microcode…
PriorityP335high7.2CVSS 3.1
AVLACHPRHUINSCCHIHAN
EPSS
0.52%
40.8th percentile
Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious CPU microcode resulting in loss of confidentiality and integrity of a confidential guest running under AMD SEV-SNP.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | amd64-microcode | < amd64-microcode 3.20250311.1~deb12u1 (bookworm) | amd64-microcode 3.20250311.1~deb12u1 (bookworm) |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N
osv7.2HIGH
vendor_debian7.2HIGH
vendor_redhat7.2HIGH
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
AMD Microcode vulnerabilities
vendor_ubuntu·2025-06-09·CVSS 5.3
CVE-2023-20584 [MEDIUM] AMD Microcode vulnerabilities
Title: AMD Microcode vulnerabilities
Summary: Several security issues were fixed in AMD Microcode.
It was discovered that AMD Microcode incorrectly handled memory addresses.
An attacker with local administrator privilege could possibly use this
issue to cause loss of integrity of a confidential guest running under AMD
SEV-SNP. (CVE-2023-20584, CVE-2023-31356)
Josh Eads, Kristoffer Janke, Eduardo Nava, Tavis Ormandy and Matteo Rizzo
discovered that AMD Microcode incorrectly verified signatures. An attacker
with local administrator privilege could possibly use this issue to cause
loss of confidentiality and integrity of a confidential guest running under
AMD SEV-SNP. (CVE-2024-56161)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary c
Ubuntu
AMD Microcode vulnerability
vendor_ubuntu·2025-06-09
CVE-2024-56161 AMD Microcode vulnerability
Title: AMD Microcode vulnerability
Summary: AMD Microcode could lose the SEV-based protection of a confidential guest.
Josh Eads, Kristoffer Janke, Eduardo Nava, Tavis Ormandy and Matteo Rizzo
discovered that AMD Microcode incorrectly verified signatures. An attacker
with local administrator privilege could possibly use this issue to cause
loss of confidentiality and integrity of a confidential guest running under
AMD SEV-SNP.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
kernel: hw:amd: Vulnerability in guest VM protected by SEV when loading malicious firmware
vendor_redhat·2025-02-03·CVSS 7.2
CVE-2024-56161 [HIGH] kernel: hw:amd: Vulnerability in guest VM protected by SEV when loading malicious firmware
kernel: hw:amd: Vulnerability in guest VM protected by SEV when loading malicious firmware
Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious CPU microcode resulting in loss of confidentiality and integrity of a confidential guest running under AMD SEV-SNP.
A vulnerability was found in hw AMD processors. This flaw allows an attacker with system administrator privileges to exploit a flaw in the microcode signature verification, enabling the loading of malicious microcode. This issue could compromise the confidentiality and integrity of guest VMs protected by AMD’s Secure Encrypted Virtualization (SEV), undermining its security.
Statement: Red Hat has very limited to no visibility and control ove
Debian
CVE-2024-56161: amd64-microcode - Improper signature verification in AMD CPU ROM microcode patch loader may allow ...
vendor_debian·2024·CVSS 7.2
CVE-2024-56161 [HIGH] CVE-2024-56161: amd64-microcode - Improper signature verification in AMD CPU ROM microcode patch loader may allow ...
Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious CPU microcode resulting in loss of confidentiality and integrity of a confidential guest running under AMD SEV-SNP.
Scope: local
bookworm: resolved (fixed in 3.20250311.1~deb12u1)
bullseye: resolved (fixed in 3.20250311.1~deb11u1)
forky: resolved (fixed in 3.20250311.1)
sid: resolved (fixed in 3.20250311.1)
trixie: resolved (fixed in 3.20250311.1)
OSV
amd64-microcode vulnerabilities
osv·2025-06-09·CVSS 6.0
CVE-2023-20584 [MEDIUM] amd64-microcode vulnerabilities
amd64-microcode vulnerabilities
It was discovered that AMD Microcode incorrectly handled memory addresses.
An attacker with local administrator privilege could possibly use this
issue to cause loss of integrity of a confidential guest running under AMD
SEV-SNP. (CVE-2023-20584, CVE-2023-31356)
Josh Eads, Kristoffer Janke, Eduardo Nava, Tavis Ormandy and Matteo Rizzo
discovered that AMD Microcode incorrectly verified signatures. An attacker
with local administrator privilege could possibly use this issue to cause
loss of confidentiality and integrity of a confidential guest running under
AMD SEV-SNP. (CVE-2024-56161)
OSV
CVE-2024-56161: Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious CPU m
osv·2025-02-03·CVSS 7.2
CVE-2024-56161 [HIGH] CVE-2024-56161: Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious CPU m
Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious CPU microcode resulting in loss of confidentiality and integrity of a confidential guest running under AMD SEV-SNP.
No detection rules found.
No public exploits indexed.
https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3019.htmlhttp://www.openwall.com/lists/oss-security/2025/02/04/1http://www.openwall.com/lists/oss-security/2025/03/06/2https://lists.debian.org/debian-lts-announce/2025/03/msg00024.htmlhttps://www.amd.com/en/resources/product-security/bulletin/amd-sb-7033.html
2025-02-03
Published