First published: Wed Oct 23 2024(Updated: )
A lack of input validation in Realtek SD card reader driver before 10.0.26100.21374 through the implementation of the IOCTL_SCSI_PASS_THROUGH control of the SD card reader driver allows an attacker to write to predictable kernel memory locations, even as a low-privileged user.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Intel Realtek SD Card Reader Driver | <10.0.26100.21374 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-40431 is considered a high severity vulnerability due to its potential for kernel memory manipulation.
To fix CVE-2024-40431, update the Realtek SD card reader driver to version 10.0.26100.21374 or later.
CVE-2024-40431 affects users of the Realtek SD card reader driver versions before 10.0.26100.21374.
CVE-2024-40431 enables low-privileged users to write to predictable kernel memory locations.
CVE-2024-40431 exploits a lack of input validation in the IOCTL_SCSI_PASS_THROUGH control of the SD card reader driver.