• News/
  • https://www.bleepingcomputer.com/news/security/amd-fixes-bug-that-lets-hackers-load-malicious-microcode-patches/

AMD fixes bug that lets hackers load malicious microcode patches

BleepingComputer
·
Sergiu Gatlan
·
Published Feb 5, 2025
·
Updated

​AMD has released mitigation and firmware updates to address a high-severity vulnerability that can be exploited to load malicious CPU microcode on unpatched devices. The security flaw (CVE-2024-56161) is caused by an improper signature verification weakness in AMD's CPU ROM microcode patch loader. Attackers with local administrator privileges can exploit this weakness, resulting in the loss of confidentiality and integrity of a confidential guest running under AMD Secure Encrypted Virtualization-Secure Nested Paging (SEV-SNP). According to AMD's development resources, SEV isolates guests and the hypervisor from one another, and SEV-SNP adds memory integrity protection that creates an isolated execution environment by helping prevent malicious hypervisor-based attacks (e.g., data replay, memory re-mapping, and more). AMD now provides mitigation requiring a microcode update on all affected platforms to block malicious microcode execution. Some platforms also require a SEV firmware update for SEV-SNP attestation, with users having to update the system BIOS and reboot to enable attestation of the mitigation. To confirm that the mitigation has been correctly installed, check whether the microcode version(s) matches the one(s) listed in the table below. "We have demonstrated the ability to craft arbitrary malicious microcode patches on Zen 1 through Zen 4 CPUs. The vulnerability is that the CPU uses an insecure hash function in the signature validation for microcode updates," the...

Read full article

Affected Software

8 affected components
AMD Cpu=Zen 1
AMD Cpu=Zen 2
AMD Cpu=Zen 3
AMD Cpu=Zen 4
AMD EPYC
AMD Ryzen 9
AMD CPU ROM microcode patch loader
AMD SEV
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a high-severity vulnerability in AMD CPUs that could allow hackers to load malicious microcode patches.

2

What security implications are discussed in the article?

The vulnerability could lead to unauthorized manipulation of CPU functionality, potentially resulting in data breaches or system compromises.

3

What specific vulnerabilities are identified in the article?

The vulnerability is identified as CVE-2024-56161, caused by improper signature verification for microcode updates.

4

Which AMD CPU models are affected by this vulnerability?

The affected AMD CPU models include Zen 1, Zen 2, Zen 3, Zen 4, and various EPYC and Ryzen 9 processors.

5

What solutions does AMD provide to mitigate this security issue?

AMD has released firmware updates and mitigation strategies to address the vulnerability and protect affected devices.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203