PT-2018-2676 · Trusted Computing · Trusted Platform Module (Tpm) 2.0

Hyoungchun Kim

+3

·

Published

2018-08-17

·

Updated

2019-10-03

·

CVE-2018-6622

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Trusted Platform Module (TPM) 2.0 (affected versions not specified)
Description The issue affects BIOS firmware producers who interpret a certain portion of the Trusted Computing Group (TCG) Trusted Platform Module (TPM) 2.0 specification in a specific way. It involves an abnormal case not being handled properly by the firmware during S3 sleep, which can clear TPM 2.0 and allow local users to overwrite static PCRs of TPM. This can neutralize the security features of TPM, such as seal/unseal and remote attestation. The vulnerability is related to errors in security settings and can impact the confidentiality, integrity, and availability of protected information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-01323
CVE-2018-6622

Affected Products

Trusted Platform Module (Tpm) 2.0