CVE-2022-25480: High severity Realtek RtsPer vulnerability
Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 allows writing to kernel memory beyond the SystemBuffer of the IRP.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-25480?
CVE-2022-25480 is rated with a medium severity due to the potential for unauthorized kernel memory access.
How do I fix CVE-2022-25480?
To fix CVE-2022-25480, update the Realtek RtsPer driver to version 10.0.22000.21355 or later, and the RtsUer driver to version 10.0.22000.31274 or later.
What systems are affected by CVE-2022-25480?
CVE-2022-25480 affects systems using Realtek RtsPer and RtsUer drivers prior to the specified secure versions.
What does CVE-2022-25480 exploit?
CVE-2022-25480 exploits a flaw that allows writing to kernel memory beyond the SystemBuffer of the IRP.
Is CVE-2022-25480 a local or remote vulnerability?
CVE-2022-25480 is considered a local vulnerability as it requires local access to exploit the driver flaw.