A security vulnerability has been discovered in Secure Encrypted Virtualization (SEV) , which under certain circumstances could allow an attacker to inject malicious microcode into the CPU.
See also: CES 2025 Press Day: What Samsung, Nvidia, AMD and Sony revealed

This particular flaw, recorded as CVE-2024-56161, has a CVSS score of 7.2/10, indicating high severity.
“Incorrect signature verification in the AMD CPU ROM microcode patch loader could allow an attacker with local administrator privileges to load malicious CPU microcode resulting in loss of privacy and integrity of a trusted guest operating under AMD SEV-SNP,” said in an advisory.
AMD credited Google security researchers Josh Eads, Kristoffer Janke, Eduardo Vela, Tavis Ormandy , and Matteo Rizzofor discovering and reporting the vulnerability on September 25, 2024.
See also: Intel: Competes with Qualcomm and AMD with second-generation Core Ultra mobile chips
SEV is an advanced security feature that uses a unique key for each virtual machine (VM), ensuring isolation both between virtual machines and from the hypervisor. On the other hand, SNP (Secure Nested Paging) adds memory integrity protections, creating a secure and isolated execution environment. At the same time, it provides protection against attacks that exploit the hypervisor, enhancing overall system security.

In a separate bulletin, Google noted that CVE-2024-56161 is the result of an insecure hash function in signature validation for microcode updates, which opens the door to a scenario where a hacker could compromise confidential computer payloads.
AMD also released a test payload to demonstrate the vulnerability, but additional technical details were withheld for another month to allow enough time for the fix to propagate throughout the supply chain.
See also: IntelBroker claims it hacked AMD's internal communications
Malicious CPU microcode refers to unauthorized or harmful modifications to the code that operates at the microarchitectural level of a central processing unit (CPU). This microcode governs the core functions of the processor, including instruction decoding, execution, and optimization processes. When compromised, malicious microcode can introduce errors, bypass security protections, or manipulate data processing in ways that are extremely difficult to detect or mitigate. Because microcode operates below the operating system level, such attacks can evade traditional security mechanisms, making them a significant cybersecurity threat .
Source: thehackernews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
