CVE-2024-36347Patch

LOWCVSS 6.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious microcode, potentially resulting in loss of integrity of x86 instruction execution, loss of confidentiality and integrity of data in x86 CPU privileged context and compromise of SMM execution environment.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-347

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-16: 1Patch / Workaround · 2026-04-16: 1Technical Details · 2026-04-16: 104-16
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
Full discourse1 post
  • ThreatCluster@threatcluster
    Patch

    BREAKING: Ubuntu issues Linux kernel patches for EntrySign CVE-2024-36347 on AMD Zen CPUs, fixing flaw that lets privileged attackers load malicious microcode. https://threatcluster.io/cluster/critical-linux-kernel-vulnerabilities-affect-amd-zen-process-d2fff390

    Post summary

    Ubuntu has released kernel patches to address CVE-2024-36347, a vulnerability that allows privileged attackers on AMD Zen CPUs to load malicious microcode.

    0000092
    155 followersView on X

Explore more