{"id":"CVE-2023-1017","details":"An out-of-bounds write vulnerability exists in TPM2.0's Module Library allowing writing of a 2-byte data past the end of TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can lead to denial of service (crashing the TPM chip/process or rendering it unusable) and/or arbitrary code execution in the TPM context.","modified":"2026-03-13T06:49:33.974200Z","published":"2023-02-28T19:15:16.657Z","related":["ALSA-2023:2453","MGASA-2023-0102","SUSE-SU-2023:2051-1","openSUSE-SU-2024:12763-1"],"references":[{"type":"WEB","url":"https://www.kb.cert.org/vuls/id/782720"},{"type":"ADVISORY","url":"https://trustedcomputinggroup.org/about/security/"},{"type":"ADVISORY","url":"https://trustedcomputinggroup.org/wp-content/uploads/TCGVRT0007-Advisory-FINAL.pdf"},{"type":"ADVISORY","url":"https://kb.cert.org/vuls/id/782720"}],"affected":[{"database_specific":{"unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"2.0-revision_1\\.16"}]},{"events":[{"introduced":"0"},{"last_affected":"2.0-revision_1\\.38"}]},{"events":[{"introduced":"0"},{"last_affected":"2.0-revision_1\\.59"}]},{"events":[{"introduced":"0"},{"fixed":"10.0.10240.19805"}]},{"events":[{"introduced":"0"},{"fixed":"10.0.14393.5786"}]},{"events":[{"introduced":"0"},{"fixed":"10.0.17763.4131"}]},{"events":[{"introduced":"0"},{"fixed":"10.0.19042.2728"}]},{"events":[{"introduced":"0"},{"fixed":"10.0.19044.2728"}]},{"events":[{"introduced":"0"},{"fixed":"10.0.19045.2728"}]},{"events":[{"introduced":"0"},{"fixed":"10.0.22000.1696"}]},{"events":[{"introduced":"0"},{"fixed":"10.0.22621.1413"}]},{"events":[{"introduced":"0"},{"fixed":"10.0.14393.5786"}]},{"events":[{"introduced":"0"},{"fixed":"10.0.17763.4131"}]},{"events":[{"introduced":"0"},{"fixed":"10.0.20348.1607"}]}],"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-1017.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}