← back
CVE-2024-56161

CVE-2024-56161

CVSS 7.2 HIGHEPSS 0.5%CWE-347
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.2EPSS 0.5%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
03 Feb 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious CPU microcode resulting in loss of confidentiality and integrity of a confidential guest running under AMD SEV-SNP.
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →