보안뉴스 아카이브
긴급도 35/100 심각도 5.9 · 보통 악용확률 10.2% CWE-208

CVE-2026-6727

Qualys 위협 인텔 · 심각도 5/5 · QID 92440 · Windows
공개 익스플로잇 실제 공격 관측 측면이동 권한상승 원격코드실행 CISA KEV
  • CVSS Temporal 9.1 (현재 위협 반영)
  • 익스플로잇 성숙도: 기능적 (3/4)
  • 공격 위치: 로컬/인증필요
  • 패치: 가능
  • 익스플로잇 프레임워크: GitHub
  • PCI-DSS 관련
A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged local attacker with access to the TPM command interface may be able to exploit timing differences to recover information that could allow decryption of ciphertexts encrypted to TPM-managed RSA keys, including the RSA Endorsement Key (EK), including import blobs, credential blobs, and session salts. Under certain conditions, this may also enable the forgery of TPM 2.0 attestations. Refer to TCGVRT0011.
KISA 보호나라 보안공지

MS 8월 보안 위협에 따른 정기 보안 업데이트 권고

KISA 원문 ↗

벡터: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N

NVD 상세 ↗   참고 링크 ↗

이 취약점을 다룬 기사 (1)

← 취약점 목록