CVE-2017-16837
—CVSS 3.0
7.8 high
EPSS
<1%p35
Published
()
Modified
Description
Certain function pointers in Trusted Boot (tboot) through 1.9.6 are not validated and can cause arbitrary code execution, which allows local users to overwrite dynamic PCRs of Trusted Platform Module (TPM) by hooking these function pointers.
- Vendors
- trusted boot project
- Products
- trusted boot
- Weakness
- CWE-20
- Vector
- CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.