First published: Tue Nov 02 2021(Updated: )
RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users to achieve a pool overflow (leading to Escalation of Privileges, Denial of Service, and Code Execution) via a crafted Device IO Control packet to a device.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Realtek RtsUpx USB Utility Driver | <=1.14.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-36924 is a vulnerability in the Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through version 1.14.0.0.
CVE-2021-36924 has a severity rating of 7.8 (high).
CVE-2021-36924 allows local low-privileged users to achieve a pool overflow, leading to Escalation of Privileges, Denial of Service, and Code Execution.
The Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio versions up to and including 1.14.0.0 are affected by CVE-2021-36924.
The vendor has released a security advisory with information on how to address CVE-2021-36924. It is recommended to follow the instructions provided by the vendor.