PT-2022-7668 · Realtek · Realtek Rtsuer Driver For Usb Card Reader+1

Published

2022-05-05

·

Updated

2024-11-05

·

CVE-2022-25479

CVSS v3.1

6.1

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
Name of the Vulnerable Software and Affected Versions Realtek RtsPer driver for PCIe Card Reader versions prior to 10.0.22000.21355 Realtek RtsUer driver for USB Card Reader versions prior to 10.0.22000.31274
Description The issue is related to memory release errors in the Realtek SD card reader device firmware. Exploitation of this issue may allow an attacker to access kernel memory from both the stack and the heap.
Recommendations For Realtek RtsPer driver for PCIe Card Reader versions prior to 10.0.22000.21355, update to version 10.0.22000.21355 or later. For Realtek RtsUer driver for USB Card Reader versions prior to 10.0.22000.31274, update to version 10.0.22000.31274 or later.

Exploit

Fix

Memory Leak

Weakness Enumeration

Related Identifiers

BDU:2024-08885
CVE-2022-25479

Affected Products

Realtek Rtsper Driver For Pcie Card Reader
Realtek Rtsuer Driver For Usb Card Reader