Vulnerability in Realtek RtsPer and RtsUer Drivers for PCIe and USB Card Readers
CVE-2022-25477

5.5MEDIUM

Key Information:

Vendor

Realtek

Vendor
CVE Published:
2 July 2024

What is CVE-2022-25477?

The vulnerability affects the Realtek RtsPer and RtsUer drivers used in PCIe and USB card readers, respectively. It allows an attacker to leak driver logs that may expose kernel mode object addresses. The leakage of these addresses can compromise Kernel Address Space Layout Randomization (KASLR), a key security feature designed to protect against various types of attacks. This exploit could lead to increased risks of privilege escalation and other security threats. Users are urged to update their drivers to the latest versions to mitigate potential exposure.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.