Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious CPU microcode resulting in loss of confidentiality and integrity of a confidential guest running under AMD SEV-SNP.
History

Wed, 02 Apr 2025 22:45:00 +0000

Type Values Removed Values Added
References

Thu, 06 Mar 2025 19:45:00 +0000


Thu, 06 Mar 2025 15:15:00 +0000


Thu, 06 Mar 2025 06:45:00 +0000

Type Values Removed Values Added
References

Wed, 12 Feb 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 04 Feb 2025 15:00:00 +0000

Type Values Removed Values Added
Title kernel: hw:amd: Vulnerability in guest VM protected by SEV when loading malicious firmware
References
Metrics threat_severity

None

threat_severity

Important


Tue, 04 Feb 2025 12:45:00 +0000

Type Values Removed Values Added
References

Mon, 03 Feb 2025 17:30:00 +0000

Type Values Removed Values Added
Description Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious CPU microcode resulting in loss of confidentiality and integrity of a confidential guest running under AMD SEV-SNP.
Weaknesses CWE-347
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: AMD

Published:

Updated: 2025-04-02T22:03:14.707Z

Reserved: 2024-12-17T21:34:57.677Z

Link: CVE-2024-56161

cve-icon Vulnrichment

Updated: 2025-04-02T22:03:14.707Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-02-03T18:15:37.280

Modified: 2025-04-02T22:15:17.963

Link: CVE-2024-56161

cve-icon Redhat

Severity : Important

Publid Date: 2025-02-03T23:00:00Z

Links: CVE-2024-56161 - Bugzilla