CVE-2021-36924: High severity realtek rts upx usb utility driver vulnerability
RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users to achieve a pool overflow (leading to Escalation of Privileges, Denial of Service, and Code Execution) via a crafted Device IO Control packet to a device.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-36924?
CVE-2021-36924 is a vulnerability in the Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through version 1.14.0.0.
What is the severity of CVE-2021-36924?
CVE-2021-36924 has a severity rating of 7.8 (high).
How does CVE-2021-36924 impact the system?
CVE-2021-36924 allows local low-privileged users to achieve a pool overflow, leading to Escalation of Privileges, Denial of Service, and Code Execution.
Which software is affected by CVE-2021-36924?
The Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio versions up to and including 1.14.0.0 are affected by CVE-2021-36924.
How can CVE-2021-36924 be fixed?
The vendor has released a security advisory with information on how to address CVE-2021-36924. It is recommended to follow the instructions provided by the vendor.