« Volver al listado

CVE-2025-1122

Estado: AnalizadaMedia (6.7)—

Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 15753.50.0 stable on Cr50 Boards allows an attacker with root access to gain persistence and Bypass operating system verification via exploiting the NV_Read functionality during the Challenge-Response process.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-1122",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-1122",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-04-15T20:43:27.223049Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.7,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 0.8
      }
    ]
  },
  "affected": [
    {
      "source": "7f6e188d-c52a-4a19-8674-3c3fa7d1fc7f",
      "affectedData": [
        {
          "vendor": "Google",
          "product": "ChromeOS",
          "versions": [
            {
              "status": "affected",
              "version": "15753.50.0",
              "lessThan": "15753.50.0",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-04-15T20:15:38.317",
  "references": [
    {
      "url": "https://issues.chromium.org/issues/b/324336238",
      "tags": [
        "Broken Link"
      ],
      "source": "7f6e188d-c52a-4a19-8674-3c3fa7d1fc7f"
    },
    {
      "url": "https://issuetracker.google.com/issues/324336238",
      "tags": [
        "Exploit",
        "Issue Tracking"
      ],
      "source": "7f6e188d-c52a-4a19-8674-3c3fa7d1fc7f"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-787"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 15753.50.0  stable on Cr50 Boards allows an attacker with root access to gain persistence and \nBypass operating system verification via exploiting the NV_Read functionality during the Challenge-Response process."
    },
    {
      "lang": "es",
      "value": "La escritura fuera de los límites en TPM2 Reference Library in Google ChromeOS 122.0.6261.132 estable en placas Cr50 permite que un atacante con acceso de root obtenga persistencia y eluda la verificación del sistema operativo mediante la explotación de la funcionalidad NV_Read durante el proceso de desafío-respuesta."
    }
  ],
  "lastModified": "2026-06-17T08:38:25.443",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:google:chrome:122.0.6261.132:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EDFC1E43-804F-419F-B8D5-861BAF5730A3"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:google:chrome_os:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "D32ACF6F-5FF7-4815-8EAD-4719F5FC9B79"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "7f6e188d-c52a-4a19-8674-3c3fa7d1fc7f"
}