Vulnerabilities in the TPM 2.0 reference implementation code
blog.quarkslab.com | vulnerability | #virtualization | #vulnerability | #tpm | #cve-2023-1017 | #cve-2023-1018 | #trusted-computing
Summary
Two flaws in the TPM 2.0 reference code — an out-of-bounds write (CVE-2023-1017) and read (CVE-2023-1018) — triggerable via malicious TPM commands, affecting virtual and hardware TPMs.
- Published
- Collected
Skip to content