Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-36347

Опубликовано: 27 июн. 2025
Источник: debian

Описание

Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious microcode, potentially resulting in loss of integrity of x86 instruction execution, loss of confidentiality and integrity of data in x86 CPU privileged context and compromise of SMM execution environment.

Примечания

  • CVE-2024-36347 is unactionable by package amd64-microcode (cf. https://bugs.debian.org/1099830#26)

  • https://bugzilla.redhat.com/show_bug.cgi?id=2336412

  • https://bughunters.google.com/blog/5424842357473280/zen-and-the-art-of-microcode-hacking

  • https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7033.html

  • https://www.openwall.com/lists/oss-security/2025/03/05/3

  • Kernel stop-gap mitigation: https://www.openwall.com/lists/oss-security/2025/03/06/3

  • https://git.kernel.org/linus/bb2281fb05e50108ce95c43ab7e701ee564565c8

  • https://www.openwall.com/lists/oss-security/2025/11/01/1

Связанные уязвимости

CVSS3: 6.4
ubuntu
7 месяцев назад

Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious microcode, potentially resulting in loss of integrity of x86 instruction execution, loss of confidentiality and integrity of data in x86 CPU privileged context and compromise of SMM execution environment.

CVSS3: 7.5
redhat
11 месяцев назад

Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious microcode, potentially resulting in loss of integrity of x86 instruction execution, loss of confidentiality and integrity of data in x86 CPU privileged context and compromise of SMM execution environment.

CVSS3: 6.4
nvd
7 месяцев назад

Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious microcode, potentially resulting in loss of integrity of x86 instruction execution, loss of confidentiality and integrity of data in x86 CPU privileged context and compromise of SMM execution environment.

CVSS3: 6.4
github
7 месяцев назад

Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious microcode, potentially resulting in loss of integrity of x86 instruction execution, loss of confidentiality and integrity of data in x86 CPU privileged context and compromise of SMM execution environment.

CVSS3: 6.4
fstec
больше 1 года назад

Уязвимость загрузчика обновлений микропрограммного обеспечения процессоров AMD связана с неправильной проверкой криптографической подписи. Эксплуатация уязвимости может позволить нарушителю выполнить произвольный код и отключить защиту System Management Mode (SMM)