TROYANOSYVIRUS
Retour aux CVEs

CVE-2025-1292

MEDIUM
6.7

Description

Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 122.0.6261.132 stable on Cr50 Boards allows an attacker with root access to gain persistence and bypass operating system verification via exploiting the NV_Read functionality during the Challenge-Response process.

Details CVE

Score CVSS v3.16.7
SeveriteMEDIUM
Vecteur CVSSCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Vecteur d'attaqueLOCAL
ComplexiteLOW
Privileges requisHIGH
Interaction utilisateurNONE
Publie4/15/2025
Derniere modification10/6/2025
Sourcenvd
Observations honeypot0

Produits affectes

google:chromegoogle:chrome_os

Faiblesses (CWE)

CWE-787

References

https://issues.chromium.org/issues/b/324336238(7f6e188d-c52a-4a19-8674-3c3fa7d1fc7f)
https://issuetracker.google.com/issues/324336238(7f6e188d-c52a-4a19-8674-3c3fa7d1fc7f)

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.