Thursday, May 15, 2025
HomeCVE/vulnerabilityBuffer Overflow Flaws in Trusted Platform Modules Allow Malicious Commands

Buffer Overflow Flaws in Trusted Platform Modules Allow Malicious Commands

Published on

SIEM as a Service

Follow Us on Google News

Trusted Computing Group’s Trust Platform Module 2.0 reference library specification has been discovered with two buffer overflow vulnerabilities that threat actors can exploit to access read-only sensitive data or overwrite normally protected data, which is only available to the TPM.

A malicious individual who has gained access to the TPM 2.0’s Command interface has the capability to take advantage of this vulnerability by sending specifically crafted commands to the module.

As a result, they can cause harm by exploiting these vulnerabilities.

- Advertisement - Google News

The Trusted Computing Group (TCG) has released a security advisory for users to mitigate and patch these vulnerabilities. 

CVE-2023-1017: Out-of-Bounds Write Vulnerability

This vulnerability exists in the TPM2.0’s Module Library, which could allow a threat actor to write 2-byte data beyond the end of TPM2.0 command in the CryptParameterDecryption routine.

Successful exploitation of this vulnerability can lead to denial of service or arbitrary code execution.

The severity of this vulnerability has been given as 7.8 (High).

CVE-2023-1018: Out-of-Bounds read vulnerability

This vulnerability exists in the TPM2.0’s Module Library, which could allow a threat actor to read 2-byte data beyond the end of TPM2.0 command in the CryptParameterDecryption routine.

Successful exploitation of this vulnerability can allow a threat actor to read or access sensitive data.

The severity of this vulnerability has been given as 5.5 (Medium).

Affected Vendors Products

Some of the Product Vendors affected by these vulnerabilities include libtpms IBM sponsored, NetBSD, NixOS, Red Hat, Squid, SUSE Linux, and Trusted Computing Group.

However, these vendors have released security patches to address these vulnerabilities.

Users of these products and vendors should upgrade to the latest versions to prevent these vulnerabilities from getting exploited.

Secures your storage & backup systems With StorageGuard – Watch a 40-second Video Tour.

Eswar
Eswar
Eswar is a Cyber security content editor with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news.

Latest articles

Coinbase Data Breach – Customers Personal Info, Government‑ID & Transaction Data Exposed

Coinbase, the largest cryptocurrency exchange in the United States, has disclosed a significant cybersecurity...

Inside Turla’s Uroboros Infrastructure and Tactics Revealed

In a nation-state cyber espionage, a recent static analysis of the Uroboros rootkit, attributed...

CISA Alerts on Five Active Zero-Day Windows Vulnerabilities Being Exploited

Cybersecurity professionals and network defenders, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

Intruder vs. Acunetix vs. Attaxion: Comparing Vulnerability Management Solutions

The vulnerability management market is projected to reach US$24.08 billion by 2030, with numerous...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Coinbase Data Breach – Customers Personal Info, Government‑ID & Transaction Data Exposed

Coinbase, the largest cryptocurrency exchange in the United States, has disclosed a significant cybersecurity...

Inside Turla’s Uroboros Infrastructure and Tactics Revealed

In a nation-state cyber espionage, a recent static analysis of the Uroboros rootkit, attributed...

CISA Alerts on Five Active Zero-Day Windows Vulnerabilities Being Exploited

Cybersecurity professionals and network defenders, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...