TPM 漏洞的虛擬智慧卡緩解計畫

套用到
Windows 10, version 1703, all editions Windows Server 2016 Windows Server 2016 Essentials Windows Server 2016 Standard Windows 10 Windows 10, version 1511, all editions Windows 10, version 1607, all editions Windows Server 2012 R2 Datacenter Windows Server 2012 R2 Standard Windows Server 2012 R2 Essentials Windows Server 2012 R2 Foundation Windows 8.1 Enterprise Windows 8.1 Pro Windows 8.1 Windows RT 8.1 Windows Server 2012 Datacenter Windows Server 2012 Standard Windows Server 2012 Essentials Windows Server 2012 Foundation Windows Server 2008 R2 Service Pack 1 Windows Server 2008 R2 Datacenter Windows Server 2008 R2 Enterprise Windows Server 2008 R2 Standard Windows Server 2008 R2 Web Edition Windows Server 2008 R2 Foundation Windows 7 Service Pack 1 Windows 7 Ultimate Windows 7 Enterprise Windows 7 Professional Windows 7 Home Premium Windows 7 Home Basic Windows 7 Starter Windows Vista Service Pack 2 Windows Vista Home Basic Windows Vista Home Premium Windows Vista Business Windows Vista Ultimate Windows Vista Enterprise Windows Vista Starter Windows Server 2008 Service Pack 2 Windows Server 2008 Foundation Windows Server 2008 Standard Windows Server 2008 for Itanium-Based Systems Windows Server 2008 Web Edition Windows Server 2008 Enterprise Windows Server 2008 Datacenter

摘要

某些可信平台模組 (TPM) 晶片組存在安全漏洞。 這種脆弱性削弱了關鍵優勢。

想了解更多關於這個漏洞的資訊,請前往 ADV170012

更多資訊

重要

由於虛擬智慧卡 (VSC) 金鑰僅儲存在 TPM 中,任何使用受影響 TPM 的裝置都可能受到威脅。

當 OEM 提供 TPM 韌體更新時,請依照 Vsc Microsoft 安全諮詢ADV170012討論的步驟來減輕 TPM 的漏洞。  Microsoft 將隨著更多緩解措施的出現而更新此文件。

安裝 TPM 韌體更新前,請先取得任何 BitLocker 或裝置加密金鑰。

首先取得鑰匙非常重要。 若 TPM 韌體更新過程中發生故障,且 BitLocker 未被暫停或裝置加密啟動,復原金鑰將需重新啟動系統。

如果裝置啟用了 BitLocker 或裝置加密,務必取得恢復金鑰。 以下是一個如何顯示單一磁碟區 BitLocker 與裝置加密恢復金鑰的範例。 如果有多個硬碟分割區,每個分割區可能會有獨立的復原金鑰。 記得記得把作業系統磁碟的復原金鑰存起來 (通常是 C) 。  如果你的作業系統磁碟區安裝在不同的磁碟區,請相應調整參數。

請在擁有管理員權限的命令提示字元執行以下腳本:

C:\Windows\system32>manage-bde -protectors -get c:

BitLocker Drive Encryption: Configuration Tool version 10.0.15063

Copyright (C) 2013 Microsoft Corporation. All rights reserved.

Volume C: []

All Key Protectors

TPM:

ID: {36B6DEE1-7B13-4A8F-876E-04735E8D3972}

PCR Validation Profile:

7, 11

(Uses Secure Boot for integrity validation)

Numerical Password:

ID: {6303FEBD-E4C0-4912-A331-4689B04E431A}

Password:

588214-228690-421003-079299-589270-595331-473407-0361

如果作業系統磁碟區啟用了 BitLocker 或裝置加密,請暫停該磁碟區。 以下是一個如何暫停 BitLocker 或裝置加密的範例。  (如果你的作業系統磁碟區安裝在不同的磁碟區,請相應地更改參數) 。

請在擁有管理員權限的命令提示字元執行以下腳本:

C:\Windows\system32>manage-bde -protectors c: -disable

BitLocker Drive Encryption: Configuration Tool version 10.0.15063

Copyright (C) 2013 Microsoft Corporation. All rights reserved.

Key protectors are disabled for volume C:.

         在 Windows 8 及更新版本中,BitLocker 與裝置加密會在一次重啟後自動恢復。 因此,請確保在安裝 TPM 韌體更新前 立即 暫停 BitLocker 和裝置加密。 在 Windows 7 及更早版本的系統中,安裝韌體更新後必須手動重新啟用 BitLocker。

安裝相應的韌體更新,依照 OEM 說明更新受影響的 TPM

這是你的 OEM 發布的更新,用來修復 TPM 中的漏洞。 請參閱Microsoft安全諮詢ADV170012中的步驟4:「套用適用的韌體更新」,了解如何從您的 OEM 取得 TPM 更新。

刪除並重新註冊 VSC

TPM 韌體更新後,必須刪除弱金鑰。 我們建議您使用 VSC 合作夥伴提供的管理工具,例如 Intercede) ,刪除現有 VSC 並重新註冊 (。