CVE detail
CVE-2023-1017
An out-of-bounds write vulnerability exists in TPM2.0's Module Library allowing writing of a 2-byte data past the end of TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can lead to denial of service (crashing the TPM chip/process or rendering it unusable) and/or arbitrary code execution in the TPM context.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 11.0 · diversity 6.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
2 source links · newest first
Two vulnerabilities affecting the Trusted Platform Module (TPM) 2.0 library could potentially lead to information disclosure or privilege escalation. The Trusted Computing Group (TCG) is warning of two vulnerabilities affecting the implementations of the Trusted Platform Module (TPM) 2.0 that could potentially lead to information disclosure or privilege escalation. The Trusted Platform Module (TPM) technology […]
newssecurityaffairs.comMar 3, 2023, 1:49 PM- Security Defects in TPM 2.0 Spec Raise AlarmSecurityWeek
Security defects in the Trusted Platform Module (TPM) 2.0 reference library specification expose devices to code execution attacks.
newswww.securityweek.comFeb 28, 2023, 9:50 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2023-28252CVSS 7.8 · High
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- CVE-2023-23376CVSS 7.8 · High
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- CVE-2022-41128CVSS 8.8 · High
Windows Scripting Languages Remote Code Execution Vulnerability
- CVE-2022-41125CVSS 7.8 · High
Windows CNG Key Isolation Service Elevation of Privilege Vulnerability
- CVE-2022-41073CVSS 7.8 · High
Windows Print Spooler Elevation of Privilege Vulnerability
- CVE-2023-1018CVSS 5.5 · Medium
An out-of-bounds read vulnerability exists in TPM2.0's Module Library allowing a 2-byte read past the end of a TPM2.0 command in the CryptParameterDecryption routine. An attacker…