Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2023-22745— Buffer Overlow in TSS2_RC_Decode in tpm2-tss

Quick assessment

Affected
tpm2-software tpm2-tss
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Peter Huewe tpm2-tss是 Peter Huewe开源的一个应用程序。用于实现可信赖计算组(TCG)TPM2软件堆栈(TSS)的源代码。 tpm2-tss存在安全漏洞,该漏洞源于存在缓冲区溢出问题。攻击者利用该漏洞可以执行任意代码。

CVSS 6.4 · Medium EPSS 0.52% · P42
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2023-22745

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Buffer Overlow in TSS2_RC_Decode in tpm2-tss
Source: CVE Program / CVE List V5
Vulnerability Description
tpm2-tss is an open source software implementation of the Trusted Computing Group (TCG) Trusted Platform Module (TPM) 2 Software Stack (TSS2). In versions prior to 4.1.0-rc0, 4.0.1, and 3.2.2-rc1, `Tss2_RC_SetHandler` and `Tss2_RC_Decode` both index into `layer_handler` with an 8 bit layer number, but the array only has `TPM2_ERROR_TSS2_RC_LAYER_COUNT` entries, so trying to add a handler for higher-numbered layers or decode a response code with such a layer number reads/writes past the end of the buffer. This Buffer overrun, could result in arbitrary code execution. An example attack would be a MiTM bus attack that returns 0xFFFFFFFF for the RC. Given the common use case of TPM modules an attacker must have local access to the target machine with local system privileges which allows access to the TPM system. Usually TPM access requires administrative privilege. Versions 4.1.0-rc0, 4.0.1, and 3.2.2-rc1 fix the issue.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
未进行输入大小检查的缓冲区拷贝(传统缓冲区溢出)
Source: CVE Program / CVE List V5
Vulnerability Title
tpm2-tss 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Peter Huewe tpm2-tss是 Peter Huewe开源的一个应用程序。用于实现可信赖计算组(TCG)TPM2软件堆栈(TSS)的源代码。 tpm2-tss存在安全漏洞,该漏洞源于存在缓冲区溢出问题。攻击者利用该漏洞可以执行任意代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
tpm2-software tpm2-tss < 4.0.1 -

II. Public POCs for CVE-2023-22745

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-22745

请登录查看更多情报信息。

Patches & Fixes for CVE-2023-22745 (1)

Vendor Advisories for CVE-2023-22745 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2023-22745

No comments yet


Leave a comment