Skip to content
GoogleGHSA-4xq7-4mgh-gp6w

AMD: Microcode Signature Verification Vulnerability

High7.2CVE-2024-56161 · Published Feb 3, 2025 · updated Apr 8, 2025

### Summary Google Security Team has identified a security vulnerability in some AMD Zen-based CPUs. This vulnerability allows an adversary with local administrator privileges (ring 0 from outside a VM) to load malicious microcode patches. We have demonstrated the ability to craft arbitrary malicious microcode patches on Zen 1 through Zen 4 CPUs. The vulnerability is that the CPU uses an insecure hash function in the signature validation for microcode updates. This vulnerability could be used by an adversary to compromise confidential computing workloads protected by the newest version of AMD Secure Encrypted Virtualization, SEV-SNP or to compromise Dynamic Root of Trust Measurement. AMD SEV-SNP users can verify the fix by confirming TCB values for SNP in their attestation reports (can be observed from a VM, consult AMD's security bulletins [AMD-SB-3019](https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3019.html) and [AMD-SB-7033](https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7033.html) for further details). ### Severity HIGH - Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrato...

GitHub advisory

Affected versions

PackageAffectedFixed in
Zen 1 (Naples)
Product
< 2024-12-132024-12-13
Zen 2 (Rome)
Product
< 2024-12-132024-12-13
Zen 3 (Milan)
Product
< 2024-12-132024-12-13
Zen 4 (Genoa)
Product
< 2024-12-162024-12-16
Zen 5 (Turin)
Product
< 2025-03-042025-03-04
Details and references

### Summary Google Security Team has identified a security vulnerability in some AMD Zen-based CPUs. This vulnerability allows an adversary with local administrator privileges (ring 0 from outside a VM) to load malicious microcode patches. We have demonstrated the ability to craft arbitrary malicious microcode patches on Zen 1 through Zen 4 CPUs. The vulnerability is that the CPU uses an insecure hash function in the signature validation for microcode updates. This vulnerability could be used by an adversary to compromise confidential computing workloads protected by the newest version of AMD Secure Encrypted Virtualization, SEV-SNP or to compromise Dynamic Root of Trust Measurement. AMD SEV-SNP users can verify the fix by confirming TCB values for SNP in their attestation reports (can be observed from a VM, consult AMD's security bulletins [AMD-SB-3019](https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3019.html) and [AMD-SB-7033](https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7033.html) for further details). ### Severity HIGH - Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious CPU microcode resulting in loss of confidentiality and integrity of a confidential guest running under AMD SEV-SNP. ### Proof of Concept A test payload for Milan and Genoa CPUs that makes the RDRAND instruction return 4 can be downloaded [here](https://github.com/google/security-research/tree/master/pocs/cpus/entrysign) (applying it requires the user to be root from outside of a VM). ### Timeline **Date reported**: September 25, 2024 **Date fixed**: December 17, 2024 **Date disclosed**: February 3, 2025 ([AMD-SB-3019](https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3019.html) and [AMD-SB-7033](https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7033.html)) **Additional details published**: March 5, 2025 **Reproduced on Zen 5 and reported to AMD**: March 7, 2025 **Zen 5 added to advisory**: April 7, 2025 Google notified AMD of this vulnerability on September 25, 2024. AMD subsequently provided an embargoed fix to its customers on December 17, 2024. To coordinate with AMD, we made a one-off exception to our standard [vulnerability disclosure policy](https://about.google/appsecurity) and delayed public disclosure until today, February 3, 2025. This joint disclosure occurs 46 days after AMD shared the fix with its customers and 131 days after Google's initial report. Due to the deep supply chain, sequence and coordination required to fix this issue, we will not be sharing full details at this time in order to give users time to re-establish trust on their confidential-compute workloads. We [shared](https://bughunters.google.com/blog/5424842357473280/zen-and-the-art-of-microcode-hacking) additional details and tools on March 5, 2025. We were then able to recover the Zen 5 key on March 7, 2025 and reported this to AMD. We then jointly added Zen 5 to the list of affected products to our advisories on April 7, 2025.

CVSS 3.1
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N
Severity from
GitHub (reviewed advisory)

More Google advisories

All Google
Advisory
PaloAlto OpenConfig Plugin: Command Injection Vulnerability
High8.6Feb 19, 2025
RSync: Heap Buffer Overflow, Info Leak, Server Leaks, Path Traversal and Safe links Bypass
HighFeb 19, 2025
ENGAGE - Server Displaying Sensitive Information
LowJan 10, 2025
Integer Overflow in eBPF DEVMAP map_delete_elem Leads to Out-of-Bounds
High7.8Jan 9, 2025
Linux Kernel: Integer Overflow in eBPF XSK map_delete_elem Leads to Out-of-Bounds
High7.8Jan 9, 2025
Linux Kernel: Out of bounds Write in ksmbd_vfs_stream_write
Critical9.8Jan 9, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.