Vulnerabilities in the reference implementation of TPM 2.0 that allow access to data in the cryptochip

The reference implementation code of the TPM 2.0 (Trusted Platform Module) specification has identified vulnerabilities (CVE-2023-1017, CVE-2023-1018) that result in reading or writing data beyond the allocated buffer. An attack on implementations of cryptoprocessors using the vulnerable code may lead to the extraction or rewriting of information stored on the chip, such as cryptographic keys. The ability to overwrite data in the TPM firmware can be exploited by an attacker to run their code within the TPM context, which could, for example, be used to implement backdoors that operate on the TPM side and are not detectable from the operating system.

The vulnerabilities are caused by improper size checks of the parameters in the CryptParameterDecryption() function, allowing reading or writing of two bytes beyond the buffer passed to the ExecuteCommand() function that contains the TPM 2.0 command. Depending on the firmware implementation, the overwritten two bytes may corrupt both unused memory and data or pointers in the stack.

Exploitation of the vulnerability is carried out by sending specially formatted commands to the TPM module (the attacker must have access to the TPM interface). The issues have been resolved in the January update of the TPM 2.0 specification (1.59 Errata 1.4, 1.38 Errata 1.13, 1.16 Errata 1.6).

The open library libtpms, used for software emulation of TPM modules and integration of TPM support into hypervisors, is also affected by vulnerabilities. The vulnerability has been fixed in the libtpms version 0.9.6 release.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster