Monday, December 23, 2024
HomeCVE/vulnerabilityBuffer Overflow Flaws in Trusted Platform Modules Allow Malicious Commands

Buffer Overflow Flaws in Trusted Platform Modules Allow Malicious Commands

Published on

SIEM as a Service

Trusted Computing Group’s Trust Platform Module 2.0 reference library specification has been discovered with two buffer overflow vulnerabilities that threat actors can exploit to access read-only sensitive data or overwrite normally protected data, which is only available to the TPM.

A malicious individual who has gained access to the TPM 2.0’s Command interface has the capability to take advantage of this vulnerability by sending specifically crafted commands to the module.

As a result, they can cause harm by exploiting these vulnerabilities.

- Advertisement - SIEM as a Service

The Trusted Computing Group (TCG) has released a security advisory for users to mitigate and patch these vulnerabilities. 

CVE-2023-1017: Out-of-Bounds Write Vulnerability

This vulnerability exists in the TPM2.0’s Module Library, which could allow a threat actor to write 2-byte data beyond the end of TPM2.0 command in the CryptParameterDecryption routine.

Successful exploitation of this vulnerability can lead to denial of service or arbitrary code execution.

The severity of this vulnerability has been given as 7.8 (High).

CVE-2023-1018: Out-of-Bounds read vulnerability

This vulnerability exists in the TPM2.0’s Module Library, which could allow a threat actor to read 2-byte data beyond the end of TPM2.0 command in the CryptParameterDecryption routine.

Successful exploitation of this vulnerability can allow a threat actor to read or access sensitive data.

The severity of this vulnerability has been given as 5.5 (Medium).

Affected Vendors Products

Some of the Product Vendors affected by these vulnerabilities include libtpms IBM sponsored, NetBSD, NixOS, Red Hat, Squid, SUSE Linux, and Trusted Computing Group.

However, these vendors have released security patches to address these vulnerabilities.

Users of these products and vendors should upgrade to the latest versions to prevent these vulnerabilities from getting exploited.

Secures your storage & backup systems With StorageGuard – Watch a 40-second Video Tour.

Eswar
Eswar
Eswar is a Cyber security content editor with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news.

Latest articles

17M Patient Records Stolen in Ransomware Attack on Three California Hospitals

A staggering 17 million patient records, containing sensitive personal and medical information, have been...

WhatsApp Wins NSO in Pegasus Spyware Hacking Lawsuit After 5 Years

After a prolonged legal battle stretching over five years, WhatsApp has triumphed over NSO...

PentestGPT – A ChatGPT Powered Automated Penetration Testing Tool

GBHackers come across a new ChatGPT-powered Penetration testing Tool called "PentestGPT" that helps penetration...

Threat Actors Selling Nunu Stealer On Hacker Forums

A new malware variant called Nunu Stealer is making headlines after being advertised on underground hacker...

API Security Webinar

72 Hours to Audit-Ready API Security

APIs present a unique challenge in this landscape, as risk assessment and mitigation are often hindered by incomplete API inventories and insufficient documentation.

Join Vivek Gopalan, VP of Products at Indusface, in this insightful webinar as he unveils a practical framework for discovering, assessing, and addressing open API vulnerabilities within just 72 hours.

Discussion points

API Discovery: Techniques to identify and map your public APIs comprehensively.
Vulnerability Scanning: Best practices for API vulnerability analysis and penetration testing.
Clean Reporting: Steps to generate a clean, audit-ready vulnerability report within 72 hours.

More like this

17M Patient Records Stolen in Ransomware Attack on Three California Hospitals

A staggering 17 million patient records, containing sensitive personal and medical information, have been...

WhatsApp Wins NSO in Pegasus Spyware Hacking Lawsuit After 5 Years

After a prolonged legal battle stretching over five years, WhatsApp has triumphed over NSO...

Threat Actors Selling Nunu Stealer On Hacker Forums

A new malware variant called Nunu Stealer is making headlines after being advertised on underground hacker...