PT-2024-7499 · Realtek · Rtsper.Sys+1
Published
2024-10-14
·
Updated
2024-11-04
·
CVE-2024-40432
CVSS v2.0
6.8
Medium
| Vector | AV:L/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Realtek SD card reader driver versions before 10.0.26100.21374
Description:
The issue is related to a lack of input validation in the Realtek SD card reader driver, specifically through the implementation of the IOCTL SFFDISK DEVICE COMMAND control. This allows a privileged attacker to crash the OS. Additionally, there is a buffer overflow vulnerability in the RtsPer.sys driver, which can be exploited to write data to kernel memory beyond the system buffer IRP.
Recommendations:
For versions before 10.0.26100.21374, update to a version 10.0.26100.21374 or later to resolve the issue.
As a temporary workaround, consider restricting access to the IOCTL SFFDISK DEVICE COMMAND control to minimize the risk of exploitation.
Avoid using the RtsPer.sys driver until the issue is resolved, if possible.
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Realtek Sd Card Reader Driver
Rtsper.Sys