AMD fixes bug that lets hackers load malicious microcode patches
ID: fc3b59f4-2332-5cde-ac29-08b674f183f6
STIX ID: report--fc3b59f4-2332-5cde-ac29-08b674f183f6
Feed Name: Bleeping Computer
Threat Score
AMD disclosed CVE-2024-56161, an improper signature verification flaw in the CPU microcode patch loader affecting Zen1–Zen4 processors (EPYC/Ryzen), which allows local administrators to install arbitrary microcode and potentially compromise Secure Encrypted Virtualization SEV-SNP guests; Google published a PoC and AMD issued microcode, firmware, and BIOS mitigations and guidance to confirm installation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
