CVE-2025-1122

Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 15753.50.0 stable on Cr50 Boards allows an attacker with root access to gain persistence and Bypass operating system verification via exploiting the NV_Read functionality during the Challenge-Response process.
Configurations

No configuration.

History

06 May 2025, 01:15

Type Values Removed Values Added
Summary (en) Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 122.0.6261.132 stable on Cr50 Boards allows an attacker with root access to gain persistence and Bypass operating system verification via exploiting the NV_Read functionality during the Challenge-Response process. (en) Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 15753.50.0 stable on Cr50 Boards allows an attacker with root access to gain persistence and Bypass operating system verification via exploiting the NV_Read functionality during the Challenge-Response process.

17 Apr 2025, 20:15

Type Values Removed Values Added
Summary (en) Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 122.0.6261.132 stable on Cr50 Boards allows an attacker with root access to gain persistence and bypass operating system verification via exploiting the NV_Read functionality during the Challenge-Response process. (en) Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 122.0.6261.132 stable on Cr50 Boards allows an attacker with root access to gain persistence and Bypass operating system verification via exploiting the NV_Read functionality during the Challenge-Response process.
CWE CWE-787
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.7

16 Apr 2025, 13:25

Type Values Removed Values Added
Summary
  • (es) La escritura fuera de los límites en TPM2 Reference Library in Google ChromeOS 122.0.6261.132 estable en placas Cr50 permite que un atacante con acceso de root obtenga persistencia y eluda la verificación del sistema operativo mediante la explotación de la funcionalidad NV_Read durante el proceso de desafío-respuesta.

15 Apr 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-15 20:15

Updated : 2025-05-06 01:15


NVD link : CVE-2025-1122

Mitre link : CVE-2025-1122

CVE.ORG link : CVE-2025-1122


JSON object : View

Products Affected

No product.

CWE
CWE-787

Out-of-bounds Write