TPM2.0 vulnerable to out-of-bounds read
CVE-2023-1018
5.5MEDIUM
What is CVE-2023-1018?
An out-of-bounds read vulnerability exists in TPM2.0's Module Library allowing a 2-byte read past the end of a TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can read or access sensitive data stored in the TPM.
Affected Version(s)
TPM2.0 1.59
TPM2.0 1.38
TPM2.0 1.16
References
EPSS Score
5% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Francisco Falcon of Quarkslab
