CVE-2025-2884 is an out-of-bounds read vulnerability in the TCG TPM2.0 Reference implementation's CryptHmacSign helper function, stemming from inadequate validation of the signature scheme against the signature key's algorithm. This flaw, with a CVSS score of 6.6 (Medium), could lead to high confidentiality and availability impacts if exploited locally with low attack complexity and user interaction. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), it has garnered significant community discussion and media coverage, including mentions in major security publications regarding Microsoft's October 2025 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Trusted Computing Group | TPM2.0 | >= 0, < 1.83CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
AMD TPM Reference Implementation June 2025 Security Update
Oct 22, 2025AMD TPM Reference Implementation June 2025 Security Update
Oct 21, 2025AMD TPM Reference Implementation June 2025 Security Update
Oct 21, 2025AMD TPM Reference Implementation June 2025 Security Update
Oct 21, 2025Cert CC: CVE-2025-2884 Out-of-Bounds read vulnerability in TCG TPM2.0 reference implementation
Oct 14, 2025