An out-of-bounds read vulnerability exists in TPM2.0's Module Library allowing a 2-byte read past the end of a TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can read or access sensitive data stored in the TPM.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://trustedcomputinggroup.org/wp-content/uploads/TCGVRT0007-Advisory-FINAL.pdf | vendor advisory |
https://trustedcomputinggroup.org/about/security/ | vendor advisory |
https://kb.cert.org/vuls/id/782720 | third party advisory us government resource |