Jump to content

[Software] This new TPM 2.0 security flaw could spell big trouble for "billions" of devices


Recommended Posts

Posted

JpXukHGqkZ8gapEzDQNqRW-650-80.jpg.webp

  • Cybersecurity researchers from Quarkslab have discovered two vulnerabilities in the Trusted Platform Module (TPM) 2.0, which could spell major trouble for “billions” of devices.
  • TPM 2.0 is a chip that PC manufacturers have been adding to the motherboards since mid-2016. The technology, as Microsoft explains, is designed to provide “security-related functions”. The chip helps generate, store, and limit the use of cryptographic keys. 

    Many TPMs, the company further explains, include physical security mechanisms to make them tamper-resistant.

  •  

    TPM 2.0 flaw
    Now, researchers Francisco Falcon and Ivan Arce discovered out-of-bounds read (CVE-2023-1017) and out-of-bounds write (CVE-2023-1018) vulnerabilities, which could allow threat actors to escalate privileges and steal sensitive data from vulnerable endpoints(opens in new tab). The impact of the flaws could differ from vendor to vendor, BleepingComputer said.

     

    https://www.techradar.com/news/this-new-tpm-20-security-flaw-could-spell-big-trouble-for-billions-of-devices
Guest
This topic is now closed to further replies.
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use.