https://seclists.org/oss-sec/2025/q1/187: Xen Security Notice 2 (CVE-2024-35347) AMD CPU Microcode SignatuVerification Vulnerability
Published Mar 6, 2025
·Updated
Affected Software
2 affected components
XEN Xen
Linux Linux kernel
Frequently Asked Questions
1
What is the severity of CVE-2024-35347?
CVE-2024-35347 is considered a high-severity vulnerability due to its potential impact on system security under Host UEFI Secure Boot.
2
How do I fix CVE-2024-35347?
To mitigate CVE-2024-35347, ensure that only microcode signed by AMD is used and apply any available updates provided by your software vendor.
3
What systems are affected by CVE-2024-35347?
CVE-2024-35347 affects systems running XEN Xen and Linux kernel that utilize AMD CPUs under UEFI Secure Boot.
4
What kind of attack does CVE-2024-35347 enable?
CVE-2024-35347 enables potential attacks where unsigned code may run with elevated privileges, compromising the security of the system.
5
What is the primary risk associated with CVE-2024-35347?
The primary risk associated with CVE-2024-35347 is unauthorized access to privileged operations, which can lead to system compromise.