First published: Wed Oct 23 2024(Updated: )
A lack of input validation in Realtek SD card reader driver before 10.0.26100.21374 through the implementation of the IOCTL_SFFDISK_DEVICE_COMMAND control of the SD card reader driver allows a privileged attacker to crash the OS.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Intel Realtek SD Card Reader Driver | <10.0.26100.21374 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-40432 has a high severity rating due to its potential to allow a privileged attacker to crash the operating system.
To mitigate CVE-2024-40432, update the Realtek SD card reader driver to version 10.0.26100.21374 or later.
CVE-2024-40432 affects Realtek SD card reader driver versions prior to 10.0.26100.21374.
CVE-2024-40432 facilitates a denial-of-service attack by allowing a privileged attacker to crash the operating system.
Yes, CVE-2024-40432 is caused by a lack of input validation in the Realtek SD card reader driver.