SB2019111318 - Information disclosure in Microsoft Trusted Platform Module (TPM)
Published: November 13, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Cryptographic issues (CVE-ID: CVE-2019-16863)
The vulnerability allows a local user to bypass certain security restrictions.
The vulnerability exists in certain Trusted Platform Module (TPM) chipsets due to weakens key confidentiality protection for a specific algorithm (ECDSA). An authenticated user with physical access can decrypt encrypted data on the target system.
Remediation
Install update from vendor's website.