Heap-based Buffer Overflow in Realtek RTL8811AU Drivers Enables Local Privilege Escalation
CVE-2025-8301
7.8HIGH
What is CVE-2025-8301?
A vulnerability in the Realtek RTL8811AU driver can be exploited by local attackers to escalate privileges. This flaw exists in the N6CSet_DOT11_CIPHER_DEFAULT_KEY function, where insufficient validation of user-supplied data length allows attackers to write past the end of a fixed-length heap-based buffer. If an attacker first executes low-privileged code on the system, they can utilize this vulnerability to elevate their access to the SYSTEM context and potentially execute arbitrary code, leading to unauthorized control over the host.
Affected Version(s)
RTL8811AU 1030.38.712.2019