CVE-2023-1018 is an out-of-bounds read vulnerability in the TPM2.0 Module Library, specifically within the CryptParameterDecryption routine, affecting products from Microsoft and the Trusted Computing Group. This flaw allows a 2-byte read past the end of a TPM2.0 command. With a CVSS score of 5.5 (Medium), successful exploitation could lead to unauthorized access or reading of sensitive data stored in the TPM, although it requires local access and low privileges. There is no evidence of active exploitation, nor are there public exploit codes available in Metasploit, Nuclei, or ExploitDB. Despite this, the vulnerability has garnered significant community attention and media coverage, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0CPE matchmatch criteria | cpe:2.3:a:trustedcomputinggroup:trusted_platform_module:2.0:revision_1.16:*:*:*:*:*:* | ||
2.0CPE matchmatch criteria | cpe:2.3:a:trustedcomputinggroup:trusted_platform_module:2.0:revision_1.38:*:*:*:*:*:* | ||
2.0CPE matchmatch criteria | cpe:2.3:a:trustedcomputinggroup:trusted_platform_module:2.0:revision_1.59:*:*:*:*:*:* | ||
< 10.0.10240.19805CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x64:* | ||
< 10.0.14393.5786CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CERT/CC: CVE-2023-1018 TPM2.0 Module Library Elevation of Privilege Vulnerability
Mar 14, 2023tpm2: TCG TPM2.0 implementations vulnerable to memory corruption
Feb 28, 2023Trusted Platform Module (TPM) 2.0 out-of-bounds read/write (CVE-2023-1017, CVE-2023-1018)