CVE-2022-25477: Medium severity Realtek RtsPer vulnerability
Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 leaks driver logs that contain addresses of kernel mode objects, weakening KASLR.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-25477?
CVE-2022-25477 is considered a high-severity vulnerability due to its potential impact on kernel address space layout randomization (KASLR).
How do I fix CVE-2022-25477?
To fix CVE-2022-25477, update the Realtek RtsPer driver to version 10.0.22000.21355 or later and the RtsUer driver to version 10.0.22000.31274 or later.
What are the potential impacts of CVE-2022-25477?
CVE-2022-25477 could allow attackers to discover kernel mode object addresses, which undermines security mechanisms like KASLR and increases risk of exploitation.
Which versions of Realtek drivers are affected by CVE-2022-25477?
CVE-2022-25477 affects Realtek RtsPer driver versions before 10.0.22000.21355 and RtsUer driver versions before 10.0.22000.31274.
Is it safe to use devices with the vulnerable Realtek drivers linked to CVE-2022-25477?
Using devices with the vulnerable Realtek drivers poses a security risk and it is recommended to update them to the patched versions as soon as possible.