Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-36347

Опубликовано: 27 июн. 2025
Источник: debian
EPSS Низкий

Описание

Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious microcode, potentially resulting in loss of integrity of x86 instruction execution, loss of confidentiality and integrity of data in x86 CPU privileged context and compromise of SMM execution environment.

Примечания

  • CVE-2024-36347 is unactionable by package amd64-microcode (cf. https://bugs.debian.org/1099830#26)

  • https://bugzilla.redhat.com/show_bug.cgi?id=2336412

  • https://bughunters.google.com/blog/5424842357473280/zen-and-the-art-of-microcode-hacking

  • https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7033.html

  • https://www.openwall.com/lists/oss-security/2025/03/05/3

  • Kernel stop-gap mitigation: https://www.openwall.com/lists/oss-security/2025/03/06/3

  • https://git.kernel.org/linus/bb2281fb05e50108ce95c43ab7e701ee564565c8

  • https://www.openwall.com/lists/oss-security/2025/11/01/1

EPSS

Процентиль: 1%
0.00097
Низкий

Связанные уязвимости

CVSS3: 6.4
ubuntu
около 1 года назад

Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious microcode, potentially resulting in loss of integrity of x86 instruction execution, loss of confidentiality and integrity of data in x86 CPU privileged context and compromise of SMM execution environment.

CVSS3: 7.5
redhat
больше 1 года назад

Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious microcode, potentially resulting in loss of integrity of x86 instruction execution, loss of confidentiality and integrity of data in x86 CPU privileged context and compromise of SMM execution environment.

CVSS3: 6.4
nvd
около 1 года назад

Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious microcode, potentially resulting in loss of integrity of x86 instruction execution, loss of confidentiality and integrity of data in x86 CPU privileged context and compromise of SMM execution environment.

CVSS3: 6.4
github
около 1 года назад

Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious microcode, potentially resulting in loss of integrity of x86 instruction execution, loss of confidentiality and integrity of data in x86 CPU privileged context and compromise of SMM execution environment.

CVSS3: 6.4
fstec
больше 1 года назад

Уязвимость функции load_ucode_amd_bsp() в модуле arch/x86/kernel/cpu/microcode/amd.c ядра операционной системы Linux, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 1%
0.00097
Низкий