ThreatCluster

CVE-2024-29039 and CVE-2024-29040 Vulnerabilities in TPM Reporting

First seen 18 Feb 2026, 13:23 UTC Api.Msrc.Microsoft 46

Article Content

Browse articles
ThreatCluster

Two vulnerabilities, CVE-2024-29039 and CVE-2024-29040, were published on June 28, 2024, affecting Trusted Platform Module (TPM) implementations. CVE-2024-29039 allows attackers to misrepresent the TPM state due to a missing check, while CVE-2024-29040 fails to detect if a quote was not generated by the TPM. These vulnerabilities could lead to security breaches in systems relying on TPM for integrity verification.

Timeline

2024-06-28
CVE-2024-29039 and CVE-2024-29040 published
2026-02-18
Articles published detailing vulnerabilities