Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-1017
HistoryFeb 28, 2023 - 12:00 a.m.

CVE-2023-1017

2023-02-2800:00:00
ubuntu.com
ubuntu.com
102
tpm2.0
module library
denial of service
arbitrary code execution

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

17.7%

An out-of-bounds write vulnerability exists in TPM2.0’s Module Library
allowing writing of a 2-byte data past the end of TPM2.0 command in the
CryptParameterDecryption routine. An attacker who can successfully exploit
this vulnerability can lead to denial of service (crashing the TPM
chip/process or rendering it unusable) and/or arbitrary code execution in
the TPM context.

Bugs

Notes

Author Note
mdeslaur This is VU#782720
OSVersionArchitecturePackageVersionFilename
ubuntu22.04noarchlibtpms<Β 0.9.3-0ubuntu1.22.04.1UNKNOWN
ubuntu22.10noarchlibtpms<Β 0.9.3-0ubuntu1.22.10.1UNKNOWN

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

17.7%