Description
Description Description
Description Description
Description
VDB

GCP-2025-031

GCP-2025-031 PUBLISHED

<p><strong>Published: </strong>2025-06-10</p><h3 class="hide-from-toc" data-text="Description" id="description_11" tabindex="-1">Description</h3><table> <thead> <tr> <th width="70%">Description</th> <th>Severity</th> <th>Notes</th> </tr> </thead> <tbody> <tr> <td> <p>The <a href="https://trustedcomputinggroup.org/">Trusted Computing Group (TCG)</a> reported a Trusted Platform Module (TPM) software vulnerability, which affects <a href="https://cloud.google.com/security/shielded-cloud/shielded-vm"> Shielded VMs</a> using virtual TPM (vTPM). This vulnerability lets an authenticated local attacker read sensitive vTPM data or impact vTPM availability.</p> <p>vTPM access is usually privileged. However, some configurations may allow broader vTPM access.</p> <h4 data-text="What should I do?" id="what-should-i-do_10" tabindex="-1">What should I do?</h4> <p>No customer action is required. Google will proactively update your systems during your standard and planned maintenance windows. However, you can limit vTPM access to administrative (root) users; this action helps reduce risk to your Shielded VMs.</p> <h4 data-text="What vulnerabilities are being addressed?" id="what-vulnerabilities-are-being-addressed_7" tabindex="-1">What vulnerabilities are being addressed?</h4> <p>Vulnerability <a href="https://www.cve.org/CVERecord?id=CVE-2025-2884"> CVE-2025-2884</a> lets a local attacker that has vTPM interface access send malicious commands. These commands exploit a mismatch, which reads out-of-bounds (OOB) vTPM memory. This action can expose sensitive data. </p> </td> <td>High</td> <td> <a href="https://www.cve.org/CVERecord?id=CVE-2025-2884">CVE-2025-2884</a> </td> </tr> </tbody> </table>

Timeline

  • Jun 10, 2025 CVE Published
$ Console Community · 100/wk Open console ›