AMD has released mitigation and firmware updates to address a high-severity vulnerability that can be exploited to load malicious CPU microcode on unpatched devices. The security flaw (CVE-2024-56161) is caused by an improper signature verification weakness in AMD's CPU ROM microcode patch loader. Attackers with local administrator privileges can exploit this weakness, resulting in the loss of confidentiality and integrity of a confidential guest running under AMD Secure Encrypted Virtualization-Secure Nested Paging (SEV-SNP). According to AMD's development resources, SEV isolates guests and the hypervisor from one another, and SEV-SNP adds memory integrity protection that creates an isolated execution environment by helping prevent malicious hypervisor-based attacks (e.g., data replay, memory re-mapping, and more). AMD now provides mitigation requiring a microcode update on all affected platforms to block malicious microcode execution. Some platforms also require a SEV firmware update for SEV-SNP attestation, with users having to update the system BIOS and reboot to enable attestation of the mitigation. To confirm that the mitigation has been correctly installed, check whether the microcode version(s) matches the one(s) listed in the table below. "We have demonstrated the ability to craft arbitrary malicious microcode patches on Zen 1 through Zen 4 CPUs. The vulnerability is that the CPU uses an insecure hash function in the signature validation for microcode updates," the...
AMD fixes bug that lets hackers load malicious microcode patches
BleepingComputer
·Sergiu Gatlan
·Published Feb 5, 2025
·Updated
Affected Software
8 affected components
AMD Cpu=Zen 1
AMD Cpu=Zen 2
AMD Cpu=Zen 3
AMD Cpu=Zen 4
AMD EPYC
AMD Ryzen 9
AMD CPU ROM microcode patch loader
AMD SEV
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a high-severity vulnerability in AMD CPUs that could allow hackers to load malicious microcode patches.
2
What security implications are discussed in the article?
The vulnerability could lead to unauthorized manipulation of CPU functionality, potentially resulting in data breaches or system compromises.
3
What specific vulnerabilities are identified in the article?
The vulnerability is identified as CVE-2024-56161, caused by improper signature verification for microcode updates.
4
Which AMD CPU models are affected by this vulnerability?
The affected AMD CPU models include Zen 1, Zen 2, Zen 3, Zen 4, and various EPYC and Ryzen 9 processors.
5
What solutions does AMD provide to mitigate this security issue?
AMD has released firmware updates and mitigation strategies to address the vulnerability and protect affected devices.