First published: Wed Feb 12 2020(Updated: )
Realtek NDIS driver rt640x64.sys, file version 10.1.505.2015, fails to do any size checking on an input buffer from user space, which the driver assumes has a size greater than zero bytes. To exploit this vulnerability, an attacker must send an IRP with a system buffer size of 0.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Realtek NDIS | =10.1.505.2015 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-11867 is medium with a score of 5.5.
The affected software version is Realtek NDIS driver rt640x64.sys version 10.1.505.2015.
CVE-2019-11867 exploits the vulnerability by sending an IRP with a system buffer size of 0.
At the moment, there is no known fix available for CVE-2019-11867.
The Common Weakness Enumeration (CWE) for CVE-2019-11867 is CWE-476.