Intel PTT and SPS Firmware Out-of-Bounds Read Vulnerability Allowing Denial-of-Service

Vulnerability

An out-of-bounds read vulnerability has been identified in the CryptHmacSign function of the TCG TPM 2.0 reference implementation, specifically in Version 1.83. This vulnerability arises from a lack of proper validation of the signature scheme against the algorithm of the signature key, allowing an authenticated local user to send maliciously crafted commands. Exploitation of this vulnerability could lead to unauthorized access to sensitive data or cause a denial-of-service condition on the TPM.

Impact

Exploitation of this vulnerability can result in a denial-of-service condition on the TPM, causing it to become unresponsive or unavailable for cryptographic functions. Additionally, the out-of-bounds read could potentially allow for unauthorized access to sensitive data stored in the TPM, depending on the specific implementation.

Remediation

Users are advised to update to the latest version of Intel PTT or Intel SPS firmware provided by their system manufacturer that addresses this vulnerability. TPM 2.0 vendors should also use the latest specifications and reference implementations to ensure vulnerabilities are resolved.

Added: Jun 10, 2025, 6:52 PM
Updated: Jun 10, 2025, 7:36 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.0
remediation
0.0
relevance
0.2
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.