Realtek USB FE/1GbE/2.5GbE/5GbE NIC Family - Buffer Overflow
CVE-2022-21742

6.2MEDIUM

Key Information:

Vendor

Realtek

Vendor
CVE Published:
20 June 2022

What is CVE-2022-21742?

Realtek USB driver has a buffer overflow vulnerability due to insufficient parameter length verification in the API function. An unauthenticated LAN attacker can exploit this vulnerability to disrupt services.

Affected Version(s)

USB FE/1GbE/2.5GbE/5GbE NIC Family Windows 10 10.28 <= 10.39

USB FE/1GbE/2.5GbE/5GbE NIC Family Windows 7 7.42 <= 7.53

USB FE/1GbE/2.5GbE/5GbE NIC Family Windows 8 8.49 <= 8.60

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Realtek
.