7.8
CVE-2023-1017
- EPSS 0.31%
- Veröffentlicht 28.02.2023 19:15:16
- Zuletzt bearbeitet 21.11.2024 07:38:17
- Quelle cret@cert.org
- Teams Watchlist Login
- Unerledigt Login
An out-of-bounds write vulnerability exists in TPM2.0's Module Library allowing writing of a 2-byte data past the end of TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can lead to denial of service (crashing the TPM chip/process or rendering it unusable) and/or arbitrary code execution in the TPM context.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Trustedcomputinggroup ≫ Trusted Platform Module Version2.0 Updaterevision_1.16
Trustedcomputinggroup ≫ Trusted Platform Module Version2.0 Updaterevision_1.38
Trustedcomputinggroup ≫ Trusted Platform Module Version2.0 Updaterevision_1.59
Microsoft ≫ Windows 10 1507 HwPlatformx64 Version < 10.0.10240.19805
Microsoft ≫ Windows 10 1607 HwPlatformx64 Version < 10.0.14393.5786
Microsoft ≫ Windows 10 1809 HwPlatformx64 Version < 10.0.17763.4131
Microsoft ≫ Windows 10 20h2 HwPlatformx64 Version < 10.0.19042.2728
Microsoft ≫ Windows 10 21h2 HwPlatformx64 Version < 10.0.19044.2728
Microsoft ≫ Windows 10 22h2 HwPlatformx64 Version < 10.0.19045.2728
Microsoft ≫ Windows 11 21h2 HwPlatformx64 Version < 10.0.22000.1696
Microsoft ≫ Windows 11 22h2 HwPlatformx64 Version < 10.0.22621.1413
Microsoft ≫ Windows Server 2016 Version < 10.0.14393.5786
Microsoft ≫ Windows Server 2019 Version < 10.0.17763.4131
Microsoft ≫ Windows Server 2022 Version < 10.0.20348.1607
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.31% | 0.537 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.