CVE-2024-36347: Medium severity vulnerability
Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious microcode, potentially resulting in loss of integrity of x86 instruction execution, loss of confidentiality and integrity of data in x86 CPU privileged context and compromise of SMM execution environment.
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-36347?
The severity of CVE-2024-36347 is classified as medium with a score of 6.4.
How do I fix CVE-2024-36347?
To fix CVE-2024-36347, ensure that you apply the latest microcode updates provided by AMD.
What impact does CVE-2024-36347 have on systems?
CVE-2024-36347 may allow an attacker with local administrator privileges to load malicious microcode, compromising the integrity and confidentiality of data.
Is CVE-2024-36347 currently being exploited?
Yes, CVE-2024-36347 is flagged as being exploited in the wild.
What are the required privileges to exploit CVE-2024-36347?
Exploitation of CVE-2024-36347 requires local administrator privileges.