CVE-2023-1018
published 2023-02-28CVE-2023-1018: An out-of-bounds read vulnerability exists in TPM2.0's Module Library allowing a 2-byte read past the end of a TPM2.0 command in the CryptParameterDecryption…
PriorityP431medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
5.55%
92.0th percentile
An out-of-bounds read vulnerability exists in TPM2.0's Module Library allowing a 2-byte read past the end of a TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can read or access sensitive data stored in the TPM.
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libtpms | < libtpms 0.9.2-3.1 (bookworm) | libtpms 0.9.2-3.1 (bookworm) |
| libtpms_project | libtpms | >= 0 < 0.9.2-3.1 | 0.9.2-3.1 |
| libtpms_project | libtpms | >= 0 < 0.9.2-3.1 | 0.9.2-3.1 |
| libtpms_project | libtpms | >= 0 < 0.9.2-3.1 | 0.9.2-3.1 |
| libtpms_project | libtpms | >= 0 < 0.9.3-0ubuntu1.22.04.1 | 0.9.3-0ubuntu1.22.04.1 |
| microsoft | windows_10_1507 | < 10.0.10240.19805 | 10.0.10240.19805 |
| microsoft | windows_10_1607 | < 10.0.14393.5786 | 10.0.14393.5786 |
| microsoft | windows_10_1809 | < 10.0.17763.4131 | 10.0.17763.4131 |
| microsoft | windows_10_20h2 | < 10.0.19042.2728 | 10.0.19042.2728 |
| microsoft | windows_10_21h2 | < 10.0.19044.2728 | 10.0.19044.2728 |
| microsoft | windows_10_22h2 | < 10.0.19045.2728 | 10.0.19045.2728 |
| microsoft | windows_11_21h2 | < 10.0.22000.1696 | 10.0.22000.1696 |
| microsoft | windows_11_22h2 | < 10.0.22621.1413 | 10.0.22621.1413 |
| microsoft | windows_server_2016 | < 10.0.14393.5786 | 10.0.14393.5786 |
| microsoft | windows_server_2019 | < 10.0.17763.4131 | 10.0.17763.4131 |
| microsoft | windows_server_2022 | < 10.0.20348.1607 | 10.0.20348.1607 |
| msrc | windows_10_for_x64-based_systems | — | — |
| msrc | windows_10_version_1607_for_x64-based_systems | — | — |
| msrc | windows_10_version_1809_for_x64-based_systems | — | — |
| msrc | windows_10_version_21h2_for_x64-based_systems | — | — |
| msrc | windows_10_version_22h2_for_x64-based_systems | — | — |
| msrc | windows_11_version_21h2_for_x64-based_systems | — | — |
| msrc | windows_11_version_22h2_for_x64-based_systems | — | — |
| msrc | windows_server_2016 | — | — |
| msrc | windows_server_2019 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv7.8HIGH
vendor_msrc8.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
libtpms vulnerabilities
osv·2023-03-07·CVSS 7.8
CVE-2023-1017 [HIGH] libtpms vulnerabilities
libtpms vulnerabilities
Francisco Falcon discovered that Libtpms did not properly manage memory
when performing certain cryptographic operations. An attacker could
possibly use this issue to cause a denial of service, or possibly execute
arbitrary code. (CVE-2023-1017, CVE-2023-1018)
It was discovered that Libtpms did not properly manage memory when
handling certain commands. An attacker could possibly use this issue
to cause a denial of service.
OSV
CVE-2023-1018: An out-of-bounds read vulnerability exists in TPM2
osv·2023-02-28·CVSS 5.5
CVE-2023-1018 [MEDIUM] CVE-2023-1018: An out-of-bounds read vulnerability exists in TPM2
An out-of-bounds read vulnerability exists in TPM2.0's Module Library allowing a 2-byte read past the end of a TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can read or access sensitive data stored in the TPM.
GHSA
GHSA-cr8w-xxqw-fm2m: An out-of-bounds read vulnerability exists in TPM2
ghsa_unreviewed·2023-02-28
CVE-2023-1018 GHSA-cr8w-xxqw-fm2m: An out-of-bounds read vulnerability exists in TPM2
An out-of-bounds read vulnerability exists in TPM2.0's Module Library allowing a 2-byte read past the end of a TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can read or access sensitive data stored in the TPM.
Red Hat
libxls: heap buffer overflow in xls_parseWorkBook() in xls.c
vendor_redhat·2023-08-15·CVSS 6.5
CVE-2023-38851 [MEDIUM] CWE-125 libxls: heap buffer overflow in xls_parseWorkBook() in xls.c
libxls: heap buffer overflow in xls_parseWorkBook() in xls.c
Buffer Overflow vulnerability in libxlsv.1.6.2 allows a remote attacker to execute arbitrary code and cause a denial of service via a crafted XLS file to the xls_parseWorkBook function in xls.c:1018.
Statement: This flaw was found to be a duplicate of CVE-2023-38852. Please see https://access.redhat.com/security/cve/CVE-2023-38852 for information about affected products and security errata.
Microsoft
CERT/CC: CVE-2023-1018 TPM2.0 Module Library Elevation of Privilege Vulnerability
vendor_msrc·2023-03-14·CVSS 8.8
CVE-2023-1018 [MEDIUM] CWE-122 CERT/CC: CVE-2023-1018 TPM2.0 Module Library Elevation of Privilege Vulnerability
CERT/CC: CVE-2023-1018 TPM2.0 Module Library Elevation of Privilege Vulnerability
FAQ: Why is the CERT/CC the assigning CNA (CVE Numbering Authority)?
This CVE is regarding a vulnerability in a third party driver. CERT/CC created this CVE on behalf of the researcher who discovered the vulnerability.
Windows TPM: Windows TPM
CERT/CC: CERT/CC
Customer Action Required: Yes
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5023702
Reference: https://support.microsoft.com/help/5023702
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5023705
Reference: https://support.microsoft.com/help/5023705
Reference
Ubuntu
Libtpms vulnerabilities
vendor_ubuntu·2023-03-07·CVSS 7.8
CVE-2023-1017 [HIGH] Libtpms vulnerabilities
Title: Libtpms vulnerabilities
Summary: Several security issues were fixed in Libtpms.
Francisco Falcon discovered that Libtpms did not properly manage memory
when performing certain cryptographic operations. An attacker could
possibly use this issue to cause a denial of service, or possibly execute
arbitrary code. (CVE-2023-1017, CVE-2023-1018)
It was discovered that Libtpms did not properly manage memory when
handling certain commands. An attacker could possibly use this issue
to cause a denial of service.
Instructions: After a standard system update you need to restart any application
using Libtpms libraries to make all the necessary changes.
Red Hat
tpm2: TCG TPM2.0 implementations vulnerable to memory corruption
vendor_redhat·2023-02-28·CVSS 5.5
CVE-2023-1018 [MEDIUM] CWE-125 tpm2: TCG TPM2.0 implementations vulnerable to memory corruption
tpm2: TCG TPM2.0 implementations vulnerable to memory corruption
An out-of-bounds read vulnerability exists in TPM2.0's Module Library allowing a 2-byte read past the end of a TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can read or access sensitive data stored in the TPM.
An out-of-bound read vulnerability was found in the TPM 2.0's Module Library, which allows the reading of 2-byte data after the end of the TPM command. This flaw allows an attacker to leak confidential data stored within the libtpms context.
Package: virt:8.2/libtpms (Red Hat Enterprise Linux 8 Advanced Virtualization) - Will not fix
Package: virt:8.3/libtpms (Red Hat Enterprise Linux 8 Advanced Virtualization) - Will not fix
Package: virt:av/lib
Debian
CVE-2023-1018: libtpms - An out-of-bounds read vulnerability exists in TPM2.0's Module Library allowing a...
vendor_debian·2023·CVSS 5.5
CVE-2023-1018 [MEDIUM] CVE-2023-1018: libtpms - An out-of-bounds read vulnerability exists in TPM2.0's Module Library allowing a...
An out-of-bounds read vulnerability exists in TPM2.0's Module Library allowing a 2-byte read past the end of a TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can read or access sensitive data stored in the TPM.
Scope: local
bookworm: resolved (fixed in 0.9.2-3.1)
forky: resolved (fixed in 0.9.2-3.1)
sid: resolved (fixed in 0.9.2-3.1)
trixie: resolved (fixed in 0.9.2-3.1)
No detection rules found.
No public exploits indexed.
Qualys
The March 2023 Patch Tuesday Security Update Review | Qualys
blogs_qualys·2023-03-15·CVSS 9.8
[CRITICAL] The March 2023 Patch Tuesday Security Update Review | Qualys
#### Table of Contents
- Microsoft Patches for March 2023
- Adobe Patches for March 2023
- Zero-day Vulnerabilities Patched in March Patch Tuesday Edition
- Other Critical Severity Vulnerabilities Patched in March Patch Tuesday Edition
- Other Microsoft Vulnerability Highlights
- Microsoft Release Summary
- Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
- Rapid Response withPatch Management (PM)
- EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
- Qualys Monthly Webinar Series
- This Month in Vulnerabilities & Patches
Microsoft has released its monthly security update for March 2023. This month’s updates addressed various vulnerabilities in different products. Let’s go through this month’s Patch Tuesday details and discuss
Qualys
The March 2023 Patch Tuesday Security Update Review
blogs_qualys·2023-03-15·CVSS 9.8
[CRITICAL] The March 2023 Patch Tuesday Security Update Review
## Table of Contents
Microsoft Patches for March 2023
Adobe Patches for March 2023
Zero-day Vulnerabilities Patched in March Patch Tuesday Edition
Other Critical Severity Vulnerabilities Patched in March Patch Tuesday Edition
Other Microsoft Vulnerability Highlights
Microsoft Release Summary
Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Rapid Response withPatch Management (PM)
EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
Qualys Monthly Webinar Series
This Month in Vulnerabilities & Patches
Microsoft has released its monthly security update for March 2023. This month’s updates addressed various vulnerabilities in different products. Let’s go through this month’s Patch Tuesday details and discuss the security
Tenable
Microsoft’s March 2023 Patch Tuesday Addresses 76 CVEs (CVE-2023-23397)
blogs_tenable·2023-03-14·CVSS 9.8
[CRITICAL] Microsoft’s March 2023 Patch Tuesday Addresses 76 CVEs (CVE-2023-23397)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Crowdstrike
March 2023 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] March 2023 Patch Tuesday: Updates and Analysis
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
Bugzilla
CVE-2023-51043 kernel: use-after-free during a race condition between a nonblocking atomic commit and a driver unload in drivers/gpu/drm/drm_atomic.c
bugzilla·2024-01-24·CVSS 7.0
CVE-2023-51043 [HIGH] CVE-2023-51043 kernel: use-after-free during a race condition between a nonblocking atomic commit and a driver unload in drivers/gpu/drm/drm_atomic.c
CVE-2023-51043 kernel: use-after-free during a race condition between a nonblocking atomic commit and a driver unload in drivers/gpu/drm/drm_atomic.c
In the Linux kernel before 6.4.5, drivers/gpu/drm/drm_atomic.c has a use-after-free during a race condition between a nonblocking atomic commit and a driver unload.
https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.4.5
https://github.com/torvalds/linux/commit/4e076c73e4f6e90816b30fcd4a0d7ab365087255
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9.2 Extended Update Support
Via RHSA-2024:1019 https://access.redhat.com/errata/RHSA-2024:1019
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9.2 Extended Update Support
Via RHSA-2024:1018 https://ac
https://kb.cert.org/vuls/id/782720https://trustedcomputinggroup.org/about/security/https://trustedcomputinggroup.org/wp-content/uploads/TCGVRT0007-Advisory-FINAL.pdfhttps://kb.cert.org/vuls/id/782720https://trustedcomputinggroup.org/about/security/https://trustedcomputinggroup.org/wp-content/uploads/TCGVRT0007-Advisory-FINAL.pdfhttps://www.kb.cert.org/vuls/id/782720
2023-02-28
Published