PT-2024-7499 · Realtek · Rtsper.Sys+1

Published

2024-10-14

·

Updated

2024-11-04

·

CVE-2024-40432

CVSS v2.0

6.8

Medium

VectorAV:L/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Realtek SD card reader driver versions before 10.0.26100.21374
Description: The issue is related to a lack of input validation in the Realtek SD card reader driver, specifically through the implementation of the IOCTL SFFDISK DEVICE COMMAND control. This allows a privileged attacker to crash the OS. Additionally, there is a buffer overflow vulnerability in the RtsPer.sys driver, which can be exploited to write data to kernel memory beyond the system buffer IRP.
Recommendations: For versions before 10.0.26100.21374, update to a version 10.0.26100.21374 or later to resolve the issue. As a temporary workaround, consider restricting access to the IOCTL SFFDISK DEVICE COMMAND control to minimize the risk of exploitation. Avoid using the RtsPer.sys driver until the issue is resolved, if possible.

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2024-08882
CVE-2024-40432

Affected Products

Realtek Sd Card Reader Driver
Rtsper.Sys