CVE-2023-1018
published 2023-02-28CVE-2023-1018: An out-of-bounds read vulnerability exists in TPM2.0's Module Library allowing a 2-byte read past the end of a TPM2.0 command in the CryptParameterDecryption…
medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
An out-of-bounds read vulnerability exists in TPM2.0's Module Library allowing a 2-byte read past the end of a TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can read or access sensitive data stored in the TPM.
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libtpms | < libtpms 0.9.2-3.1 (bookworm) | libtpms 0.9.2-3.1 (bookworm) |
| libtpms_project | libtpms | >= 0 < 0.9.2-3.1 | 0.9.2-3.1 |
| libtpms_project | libtpms | >= 0 < 0.9.2-3.1 | 0.9.2-3.1 |
| libtpms_project | libtpms | >= 0 < 0.9.2-3.1 | 0.9.2-3.1 |
| libtpms_project | libtpms | >= 0 < 0.9.3-0ubuntu1.22.04.1 | 0.9.3-0ubuntu1.22.04.1 |
| microsoft | windows_10_1507 | < 10.0.10240.19805 | 10.0.10240.19805 |
| microsoft | windows_10_1607 | < 10.0.14393.5786 | 10.0.14393.5786 |
| microsoft | windows_10_1809 | < 10.0.17763.4131 | 10.0.17763.4131 |
| microsoft | windows_10_20h2 | < 10.0.19042.2728 | 10.0.19042.2728 |
| microsoft | windows_10_21h2 | < 10.0.19044.2728 | 10.0.19044.2728 |
| microsoft | windows_10_22h2 | < 10.0.19045.2728 | 10.0.19045.2728 |
| microsoft | windows_11_21h2 | < 10.0.22000.1696 | 10.0.22000.1696 |
| microsoft | windows_11_22h2 | < 10.0.22621.1413 | 10.0.22621.1413 |
| microsoft | windows_server_2016 | < 10.0.14393.5786 | 10.0.14393.5786 |
| microsoft | windows_server_2019 | < 10.0.17763.4131 | 10.0.17763.4131 |
| microsoft | windows_server_2022 | < 10.0.20348.1607 | 10.0.20348.1607 |
| msrc | windows_10_for_x64-based_systems | — | — |
| msrc | windows_10_version_1607_for_x64-based_systems | — | — |
| msrc | windows_10_version_1809_for_x64-based_systems | — | — |
| msrc | windows_10_version_21h2_for_x64-based_systems | — | — |
| msrc | windows_10_version_22h2_for_x64-based_systems | — | — |
| msrc | windows_11_version_21h2_for_x64-based_systems | — | — |
| msrc | windows_11_version_22h2_for_x64-based_systems | — | — |
| msrc | windows_server_2016 | — | — |
| msrc | windows_server_2019 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv7.8HIGH