First published: Tue Jul 02 2024(Updated: )
Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 allows writing to kernel memory beyond the SystemBuffer of the IRP.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Realtek RtsPer | <10.0.22000.21355 | |
Realtek RTSUER | <10.0.22000.31274 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-25480 is rated with a medium severity due to the potential for unauthorized kernel memory access.
To fix CVE-2022-25480, update the Realtek RtsPer driver to version 10.0.22000.21355 or later, and the RtsUer driver to version 10.0.22000.31274 or later.
CVE-2022-25480 affects systems using Realtek RtsPer and RtsUer drivers prior to the specified secure versions.
CVE-2022-25480 exploits a flaw that allows writing to kernel memory beyond the SystemBuffer of the IRP.
CVE-2022-25480 is considered a local vulnerability as it requires local access to exploit the driver flaw.