CVE-2025-2884: CWE-125 Out-of-bounds Read in Trusted Computing Group TPM2.0
CVE-2025-2884 is a medium severity vulnerability in the Trusted Computing Group's TPM 2.0 software affecting Shielded VMs using virtual TPM (vTPM). It allows an authenticated local attacker with vTPM interface access to perform out-of-bounds reads of vTPM memory, potentially exposing sensitive data and impacting availability. The vulnerability requires local privileges and user interaction. No customer action is required as Google will update affected systems during planned maintenance. Limiting vTPM access to administrative users can reduce risk.
AI Analysis
Technical Summary
CVE-2025-2884 is an out-of-bounds read vulnerability (CWE-125) in the Trusted Computing Group's TPM 2.0 implementation, specifically affecting virtual TPMs used in Shielded VMs. An authenticated local attacker with access to the vTPM interface can send crafted commands that exploit a mismatch in memory handling, causing out-of-bounds reads of vTPM memory. This can lead to disclosure of sensitive vTPM data and impact vTPM availability. The vulnerability is rated with a CVSS 3.1 score of 6.6 (medium severity), requiring local access with low complexity and user interaction. Some configurations may allow broader vTPM access beyond privileged users, increasing risk. Vendor guidance indicates no immediate customer action is needed as updates will be applied proactively during maintenance windows.
Potential Impact
An authenticated local attacker with access to the vTPM interface can read sensitive memory beyond intended bounds, potentially exposing confidential vTPM data. Additionally, the vulnerability can impact the availability of the vTPM, which is critical for Shielded VM security. The attack requires local privileges and user interaction, limiting remote exploitation. The impact includes confidentiality loss and availability disruption but no integrity impact is indicated.
Mitigation Recommendations
No customer action is required as the vendor (Google) will proactively update affected systems during standard maintenance windows. To reduce risk, it is recommended to restrict vTPM access to administrative (root) users, limiting the potential attacker base. Monitor vendor advisories for any future updates or patches. Patch status is not explicitly confirmed; check vendor advisories for current remediation guidance.
CVE-2025-2884: CWE-125 Out-of-bounds Read in Trusted Computing Group TPM2.0
Description
CVE-2025-2884 is a medium severity vulnerability in the Trusted Computing Group's TPM 2.0 software affecting Shielded VMs using virtual TPM (vTPM). It allows an authenticated local attacker with vTPM interface access to perform out-of-bounds reads of vTPM memory, potentially exposing sensitive data and impacting availability. The vulnerability requires local privileges and user interaction. No customer action is required as Google will update affected systems during planned maintenance. Limiting vTPM access to administrative users can reduce risk.
CVSS v3.1
Score 6.6medium
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-2884 is an out-of-bounds read vulnerability (CWE-125) in the Trusted Computing Group's TPM 2.0 implementation, specifically affecting virtual TPMs used in Shielded VMs. An authenticated local attacker with access to the vTPM interface can send crafted commands that exploit a mismatch in memory handling, causing out-of-bounds reads of vTPM memory. This can lead to disclosure of sensitive vTPM data and impact vTPM availability. The vulnerability is rated with a CVSS 3.1 score of 6.6 (medium severity), requiring local access with low complexity and user interaction. Some configurations may allow broader vTPM access beyond privileged users, increasing risk. Vendor guidance indicates no immediate customer action is needed as updates will be applied proactively during maintenance windows.
Potential Impact
An authenticated local attacker with access to the vTPM interface can read sensitive memory beyond intended bounds, potentially exposing confidential vTPM data. Additionally, the vulnerability can impact the availability of the vTPM, which is critical for Shielded VM security. The attack requires local privileges and user interaction, limiting remote exploitation. The impact includes confidentiality loss and availability disruption but no integrity impact is indicated.
Mitigation Recommendations
No customer action is required as the vendor (Google) will proactively update affected systems during standard maintenance windows. To reduce risk, it is recommended to restrict vTPM access to administrative (root) users, limiting the potential attacker base. Monitor vendor advisories for any future updates or patches. Patch status is not explicitly confirmed; check vendor advisories for current remediation guidance.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- certcc
- Date Reserved
- 2025-03-27T21:01:41.908Z
- Cvss Version
- null
- State
- PUBLISHED
Threat ID: 68487f501b0bd07c393899c2
Added to database: 06/10/2025, 18:54:08 UTC
Last enriched: 08/04/2026, 13:27:27 UTC
Last updated: 08/05/2026, 00:41:08 UTC
Views: 169
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.