HomeSecurityAMD SEV-SNP vulnerability allows injection of malicious microcode

AMD SEV-SNP vulnerability allows injection of malicious microcode

A security vulnerability has been discovered in Secure Encrypted Virtualization (SEV) , which under certain circumstances could allow an attacker to inject malicious microcode into the CPU.

See also: CES 2025 Press Day: What Samsung, Nvidia, AMD and Sony revealed

AMD vulnerability

This particular flaw, recorded as CVE-2024-56161, has a CVSS score of 7.2/10, indicating high severity.

Incorrect signature verification in the AMD CPU ROM microcode patch loader could allow an attacker with local administrator privileges to load malicious CPU microcode resulting in loss of privacy and integrity of a trusted guest operating under AMD SEV-SNP,” said in an advisory.

AMD credited Google security researchers Josh Eads, Kristoffer Janke, Eduardo Vela, Tavis Ormandy , and Matteo Rizzofor discovering and reporting the vulnerability on September 25, 2024.

See also: Intel: Competes with Qualcomm and AMD with second-generation Core Ultra mobile chips

SEV is an advanced security feature that uses a unique key for each virtual machine (VM), ensuring isolation both between virtual machines and from the hypervisor. On the other hand, SNP (Secure Nested Paging) adds memory integrity protections, creating a secure and isolated execution environment. At the same time, it provides protection against attacks that exploit the hypervisor, enhancing overall system security.

AMD SEV-SNP vulnerability allows injection of malicious microcode

In a separate bulletin, Google noted that CVE-2024-56161 is the result of an insecure hash function in signature validation for microcode updates, which opens the door to a scenario where a hacker could compromise confidential computer payloads.

AMD also released a test payload to demonstrate the vulnerability, but additional technical details were withheld for another month to allow enough time for the fix to propagate throughout the supply chain.

See also: IntelBroker claims it hacked AMD's internal communications

Malicious CPU microcode refers to unauthorized or harmful modifications to the code that operates at the microarchitectural level of a central processing unit (CPU). This microcode governs the core functions of the processor, including instruction decoding, execution, and optimization processes. When compromised, malicious microcode can introduce errors, bypass security protections, or manipulate data processing in ways that are extremely difficult to detect or mitigate. Because microcode operates below the operating system level, such attacks can evade traditional security mechanisms, making them a significant cybersecurity threat .

Source: thehackernews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS