CVE-2024-56161

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published Feb 3, 2025
Updated: Feb 4, 2025
CWE ID 347

Summary

CVE-2024-56161 is a newly disclosed vulnerability affecting AMD CPU ROM microcode patch loaders. This issue involves improper signature verification, allowing local administrators to load malicious CPU microcode. The malicious code can result in a significant loss of confidentiality and integrity for guests running under AMD SEV-SNP, potentially putting sensitive data at risk. Attackers can exploit this vulnerability by bypassing the security checks in place to load unauthorized microcode, posing a serious threat to systems with AMD processors and vulnerable to this attack.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share