CVE detail
CVE-2023-1018
An out-of-bounds read vulnerability exists in TPM2.0's Module Library allowing a 2-byte read past the end of a TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can read or access sensitive data stored in the TPM.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 11.0 · diversity 6.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
2 source links · newest first
Two vulnerabilities affecting the Trusted Platform Module (TPM) 2.0 library could potentially lead to information disclosure or privilege escalation. The Trusted Computing Group (TCG) is warning of two vulnerabilities affecting the implementations of the Trusted Platform Module (TPM) 2.0 that could potentially lead to information disclosure or privilege escalation. The Trusted Platform Module (TPM) technology […]
newssecurityaffairs.comMar 3, 2023, 1:49 PM- Security Defects in TPM 2.0 Spec Raise AlarmSecurityWeek
Security defects in the Trusted Platform Module (TPM) 2.0 reference library specification expose devices to code execution attacks.
newswww.securityweek.comFeb 28, 2023, 9:50 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2023-24900CVSS 5.9 · Medium
Windows NTLM Security Support Provider Information Disclosure Vulnerability
- CVE-2023-24931CVSS 7.5 · High
Windows Secure Channel Denial of Service Vulnerability
- CVE-2023-24924CVSS 8.8 · High
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
- CVE-2023-24872CVSS 8.8 · High
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
- CVE-2023-24862CVSS 5.5 · Medium
Windows Secure Channel Denial of Service Vulnerability
- CVE-2023-21798CVSS 8.8 · High
Microsoft ODBC Driver Remote Code Execution Vulnerability