CVE-2021-36925: High severity realtek rts upx usb utility driver vulnerability
RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users to achieve an arbitrary read or write operation from/to physical memory (leading to Escalation of Privileges, Denial of Service, Code Execution, and Information Disclosure) via a crafted Device IO Control packet to a device.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-36925?
CVE-2021-36925 is a vulnerability in the Realtek RtsUpx USB Utility Driver that allows local low-privileged users to achieve an arbitrary read or write operation from/to physical memory.
What is the severity of CVE-2021-36925?
CVE-2021-36925 has a severity rating of 7.8, which is considered high.
How does CVE-2021-36925 impact the system?
CVE-2021-36925 can lead to Escalation of Privileges, Denial of Service, Code Execution, and Information Disclosure on the affected system.
Which software versions are affected by CVE-2021-36925?
The Realtek RtsUpx USB Utility Driver versions up to and including 1.14.0.0 are affected by CVE-2021-36925.
How can I fix CVE-2021-36925?
To fix CVE-2021-36925, users should update their Realtek RtsUpx USB Utility Driver to a version that is not affected by the vulnerability.