An out-of-bounds read vulnerability exists in TPM2.0's Module Library allowing a 2-byte read past the end of a TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can read or access sensitive data stored in the TPM.
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.0-revision_1\\.16"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.0-revision_1\\.38"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.0-revision_1\\.59"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "10.0.10240.19805"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "10.0.14393.5786"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "10.0.17763.4131"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "10.0.19042.2728"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "10.0.19044.2728"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "10.0.19045.2728"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "10.0.22000.1696"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "10.0.22621.1413"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "10.0.14393.5786"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "10.0.17763.4131"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "10.0.20348.1607"
}
]
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-1018.json"