TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2025-1122

MEDIUM
6.7

Beschreibung

Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 15753.50.0 stable on Cr50 Boards allows an attacker with root access to gain persistence and Bypass operating system verification via exploiting the NV_Read functionality during the Challenge-Response process.

CVE Details

CVSS v3.1 Bewertung6.7
SchweregradMEDIUM
CVSS VektorCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorLOCAL
KomplexitatLOW
Erforderliche PrivilegienHIGH
BenutzerinteraktionNONE
Veroffentlicht4/15/2025
Zuletzt geandert10/6/2025
Quellenvd
Honeypot-Sichtungen0

Betroffene Produkte

google:chromegoogle:chrome_os

Schwachen (CWE)

CWE-787

Referenzen

https://issues.chromium.org/issues/b/324336238(7f6e188d-c52a-4a19-8674-3c3fa7d1fc7f)
https://issuetracker.google.com/issues/324336238(7f6e188d-c52a-4a19-8674-3c3fa7d1fc7f)

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.