Improper Signature Verification in AMD CPU Microcode Loader
CVE-2024-36347
Key Information:
- Vendor
Amd
- Vendor
- CVE Published:
- 27 June 2025
What is CVE-2024-36347?
A vulnerability exists in the AMD CPU ROM microcode patch loader due to improper signature verification. This issue allows an attacker with local administrator privileges to inject malicious microcode, which can compromise the integrity of x86 instruction execution. The exploitation of this flaw could lead to unauthorized access and manipulation of sensitive data within a privileged x86 context, potentially affecting the secure management mode (SMM) execution environment.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
AMD Athlon™ 3000 Series Desktop Processors with Radeon™ Graphics ComboAM4PI 1.0.0.D
AMD Athlon™ 3000 Series Mobile Processors with Radeon™ Graphics PicassoPI-FP5 1.0.1.2b
AMD EPYC™ 4004 Series ComboAM5PI1.0.0.a
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved