Lucene search

K
lenovoLenovoLENOVO:PS500178-TPM-20-SLEEP-WAKE-ERROR-IN-BIOS-FIRMWARE-NOSID
HistoryJul 26, 2018 - 4:56 p.m.

TPM 2.0 Sleep-Wake Error in BIOS Firmware - Lenovo Support NL

2018-07-2616:56:00
support.lenovo.com
15

EPSS

0

Percentile

5.1%

Lenovo Security Advisory: LEN-20494

**Potential Impact:**Local security-bypass

Severity: Medium

Scope of Impact: Industry-wide

CVE Identifier: CVE-2018-6622

Summary Description:

Lenovo was notified of a potential security bypass vulnerability in BIOS firmware for managing the TPM 2.0 device. If an attacker gains Windows administrator rights and then modifies the Windows kernel so it does not properly prepare the TPM for entering sleep (S3), the TPM may later wake in an error state with cleared PCRs. The BIOS does not detect and resolve this TPM error state, potentially allowing a local attacker to bypass security measures.

Mitigation Strategy for Customers (what you should do to protect yourself):

Lenovo recommends customers update their BIOS to at least the minimum version indicated for their model in the Product Impact section of this advisory.

Product Impact:

EPSS

0

Percentile

5.1%

Related for LENOVO:PS500178-TPM-20-SLEEP-WAKE-ERROR-IN-BIOS-FIRMWARE-NOSID