5.5

CVE-2023-1018

TPM2.0 vulnerable to out-of-bounds read

An out-of-bounds read vulnerability exists in TPM2.0's Module Library allowing a 2-byte read past the end of a TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can read or access sensitive data stored in the TPM.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Trustedcomputinggroup ≫ Trusted Platform Module Version 2.0 Update revision_1.16
Trustedcomputinggroup ≫ Trusted Platform Module Version 2.0 Update revision_1.38
Trustedcomputinggroup ≫ Trusted Platform Module Version 2.0 Update revision_1.59
Microsoft ≫ Windows 10 1507 HwPlatform x64 Version < 10.0.10240.19805
Microsoft ≫ Windows 10 1607 HwPlatform x64 Version < 10.0.14393.5786
Microsoft ≫ Windows 10 1809 HwPlatform x64 Version < 10.0.17763.4131
Microsoft ≫ Windows 10 20h2 HwPlatform x64 Version < 10.0.19042.2728
Microsoft ≫ Windows 10 21h2 HwPlatform x64 Version < 10.0.19044.2728
Microsoft ≫ Windows 10 22h2 HwPlatform x64 Version < 10.0.19045.2728
Microsoft ≫ Windows 11 21h2 HwPlatform x64 Version < 10.0.22000.1696
Microsoft ≫ Windows 11 22h2 HwPlatform x64 Version < 10.0.22621.1413
Microsoft ≫ Windows Server 2016 Version < 10.0.14393.5786
Microsoft ≫ Windows Server 2019 Version < 10.0.17763.4131
Microsoft ≫ Windows Server 2022 Version < 10.0.20348.1607
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.55% 0.918
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA-ADP 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

https://trustedcomputinggroup.org/about/security/
Vendor Advisory
https://kb.cert.org/vuls/id/782720
Third Party Advisory
US Government Resource
https://trustedcomputinggroup.org/wp-content/uploads/TCGVRT0007-Advisory-FINAL.pdf
Vendor Advisory
https://www.kb.cert.org/vuls/id/782720