TPM2.0 vulnerable to out-of-bounds read
CVE-2023-1018

5.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
28 February 2023

What is CVE-2023-1018?

An out-of-bounds read vulnerability exists in TPM2.0's Module Library allowing a 2-byte read past the end of a TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can read or access sensitive data stored in the TPM.

Affected Version(s)

TPM2.0 1.59

TPM2.0 1.38

TPM2.0 1.16

References

EPSS Score

5% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Francisco Falcon of Quarkslab
.