cbcvebase.
CVE-2023-1017
published 2023-02-28

CVE-2023-1017: An out-of-bounds write vulnerability exists in TPM2.0's Module Library allowing writing of a 2-byte data past the end of TPM2.0 command in the…

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
An out-of-bounds write vulnerability exists in TPM2.0's Module Library allowing writing of a 2-byte data past the end of TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can lead to denial of service (crashing the TPM chip/process or rendering it unusable) and/or arbitrary code execution in the TPM context.

Affected

41 ranges· showing 25
VendorProductVersion rangeFixed in
debianlibtpms< libtpms 0.9.2-3.1 (bookworm)libtpms 0.9.2-3.1 (bookworm)
libtpms_projectlibtpms>= 0 < 0.9.2-3.10.9.2-3.1
libtpms_projectlibtpms>= 0 < 0.9.2-3.10.9.2-3.1
libtpms_projectlibtpms>= 0 < 0.9.2-3.10.9.2-3.1
libtpms_projectlibtpms>= 0 < 0.9.3-0ubuntu1.22.04.10.9.3-0ubuntu1.22.04.1
linuxlinux_kernel>= 0 < 5.4.2355.4.235
linuxlinux_kernel>= 3.15.0 < 5.10.2185.10.218
linuxlinux_kernel>= 5.11.0 < 5.15.1605.15.160
linuxlinux_kernel>= 5.11.0 < 5.15.995.15.99
linuxlinux_kernel>= 5.16.0 < 6.1.246.1.24
linuxlinux_kernel>= 5.16.0 < 6.1.166.1.16
linuxlinux_kernel>= 5.18.0 < 6.2.36.2.3
linuxlinux_kernel>= 5.5.0 < 5.10.1735.10.173
linuxlinux_kernel>= 6.2.0 < 6.2.116.2.11
microsoftwindows_10_1507< 10.0.10240.1980510.0.10240.19805
microsoftwindows_10_1607< 10.0.14393.578610.0.14393.5786
microsoftwindows_10_1809< 10.0.17763.413110.0.17763.4131
microsoftwindows_10_20h2< 10.0.19042.272810.0.19042.2728
microsoftwindows_10_21h2< 10.0.19044.272810.0.19044.2728
microsoftwindows_10_22h2< 10.0.19045.272810.0.19045.2728
microsoftwindows_11_21h2< 10.0.22000.169610.0.22000.1696
microsoftwindows_11_22h2< 10.0.22621.141310.0.22621.1413
microsoftwindows_server_2016< 10.0.14393.578610.0.14393.5786
microsoftwindows_server_2019< 10.0.17763.413110.0.17763.4131
microsoftwindows_server_2022< 10.0.20348.160710.0.20348.1607

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH