IM
IronMonkey Threat Research

CVE-2025-2884 MEDIUM

Published: 2025-06-10 | Last Modified: 2026-08-11 | Status: Deferred

Description

TCG TPM2.0 Reference implementation's CryptHmacSign helper function is vulnerable to Out-of-Bounds read due to the lack of validation the signature scheme with the signature key's algorithm. See Errata Revision 1.83 and advisory TCGVRT0009 for TCG standard TPM2.0

Additional Descriptions (1)

La función auxiliar CryptHmacSign de la implementación de referencia TCG TPM2.0 es vulnerable a lecturas fuera de los límites debido a la falta de validación del esquema de firma con el algoritmo de la clave de firma. Consulte la errata 1.83 del estándar TCG TPM2.0.

CVSS Metrics

Base Score: 6.6 (MEDIUM)

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H

Attack VectorLOCAL
Attack ComplexityLOW
Privileges RequiredLOW
User InteractionREQUIRED
ScopeUNCHANGED
Confidentiality ImpactHIGH
Integrity ImpactNONE
Availability ImpactHIGH

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0

Type: Secondary

Exploitability Score: 1.3

Impact Score: 5.2

Weaknesses

Source Type Description
134c704f-9b21-4f2e-91b3-4a467353bcc0 Secondary
en CWE-125
Notification
Message here