An out-of-bounds write vulnerability exists in TPM2.0's Module Library allowing writing of a 2-byte data past the end of TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can lead to denial of service (crashing the TPM chip/process or rendering it unusable) and/or arbitrary code execution in the TPM context.
For more information on this vulnerability please visit: https://nvd.nist.gov/vuln/detail/CVE-2023-1017
CVSS 3: 7.8
Product | Package | Status |
Lighthouse | - | Not impacted |
OM1200 OM2200 CM8100 |
TPM2 |
Not impacted |
Classic Console Servers IM7200 CM7100 ACM7000 |
- | Not impacted |
Comments
0 comments
Please sign in to leave a comment.