ZDI-25-881: Realtek RTL8811AU rtwlanu.sys N6CQueryInformationHandleCustomized11nOids Out-Of-Bounds Read Information Disclosure Vulnerability
This vulnerability allows local attackers to disclose sensitive information on affected installations of Realtek RTL8811AU drivers. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the N6CQueryInformationHandleCustomized11nOids function. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the kernel.
Other sources
This vulnerability allows local attackers to disclose sensitive information on affected installations of Realtek RTL8811AU drivers. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 3.8. The following CVEs are assigned: CVE-2025-8298.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-881?
The severity of ZDI-25-881 is considered to be critical due to its potential to disclose sensitive information.
How do I fix ZDI-25-881?
To fix ZDI-25-881, ensure you update the Realtek RTL8811AU drivers to the latest version provided by the manufacturer.
Who is affected by ZDI-25-881?
ZDI-25-881 affects users of Realtek RTL8811AU drivers running on systems where low-privileged code can be executed.
What type of information can be disclosed by ZDI-25-881?
ZDI-25-881 may allow local attackers to disclose sensitive information stored on the affected system.
What are the prerequisites for exploiting ZDI-25-881?
An attacker must gain the ability to execute low-privileged code on the target system to exploit ZDI-25-881.