Impact
The vulnerability is an information leakage in the TCG TPM 2.0 reference code that lets a local attacker with elevated privileges extract a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key). With this credential the attacker can forge TPM 2.0 attestations, effectively compromising the integrity of services that rely on TPM attestations. This weakness corresponds to improper type conversion or cast (CWE-704).
Affected Systems
The impact is limited to implementations that use the Trusted Computing Group TPM 2.0 reference code. No specific release numbers are listed; therefore any instance of the reference code that has not been updated to the latest patch set may be vulnerable. The vulnerability applies to all products that rely on this reference code for TPM key handling and attestation.
Risk and Exploitability
The flaw is local; the attacker must have privileged or elevated local access. The CVSS score of 7.9 indicates a high severity. EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet seen widespread exploitation. Nonetheless, the ability to forge attestations could severely undermine security controls that rely on TPM attestations. Despite the low exploitation probability, the impact on integrity is significant, making it a high risk for systems that rely on TPM for authentication or attestation.
OpenCVE Enrichment