Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-29039

24
FAUCET Score

CVE-2024-29039 affects tpm2_tools, allowing attackers to manipulate tpm2_checkquote outputs by altering the PCR input file, leading to incorrect mapping of digest values and a misleading representation of the TPM state. This high-severity vulnerability (CVSS 8.1) has a network attack vector and high impact on confidentiality, integrity, and availability, but requires high attack complexity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion. The issue has been patched in tpm2_tools version 5.7.

Impacted Technologies

VendorProductVersion(s)CPE
< 5.7CPE matchmatch criteria
cpe:2.3:a:tpm2-tools_project:tpm2-tools:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.0CRITICAL

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.2
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.98%
Probability of exploitation in next 30 days
EPSS Percentile
58.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0098 is in the 23rd percentile among its peer group of 8,915 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (9)

microsoftpatch availablevia msrc
Product: cbl2 tpm2-tools 4.3.2-2 on CBL Mariner 2.0Fixed in: 4.3.2-2
microsoftpatch availablevia msrc
Product: 17702-17084Fixed in: 5.5.1-1
microsoftpatch availablevia msrc
Product: 20280-17086Fixed in: 4.3.2-2
microsoftpatch availablevia msrc
Product: azl3 tpm2-tools 5.5.1-1 on Azure Linux 3.0Fixed in: 5.5.1-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 4.3.2-2
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 4.3.2-2
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: tpm2-tools-0:5.2-4.el9
View patch
github_advisoryworkaround availablevia nvd_reference
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: tpm2-tools

Vendor Advisories (3)

microsoft2024-Jul/CVE-2024-29039

CVE-2024-29039

Jul 9, 2024
microsoft2024-Jun/CVE-2024-29039Critical

Missing check in tpm2_checkquote allows attackers to misrepresent the TPM state

Jun 11, 2024
redhatCVE-2024-29039Low

tpm2-tools: pcr selection value is not compared with the attest

Apr 30, 2024

References

lists.fedoraproject.org / archives/list/[email protected]/message/EFR7SVEWCOXORHPCLLGXEMHFMIGG2MFE
lists.fedoraproject.org / archives/list/[email protected]/message/GI4JFEZBKQQUPJ4RWK6IHEWXAFCEJDPI
github.com / tpm2-software/tpm2-tools/releases/tag/5.7
Release Notes
github.com / tpm2-software/tpm2-tools/security/advisories/GHSA-8rjm-5f5f-h4q6
ExploitMitigationVendor Advisory