CVE-2022-25477

Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 leaks driver logs that contain addresses of kernel mode objects, weakening KASLR.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:realtek:rtsper:*:*:*:*:*:*:*:*
cpe:2.3:a:realtek:rtsuer:*:*:*:*:*:*:*:*

History

24 Oct 2024, 17:15

Type Values Removed Values Added
References
  • () https://zwclose.github.io/2024/10/14/rtsper1.html -

21 Aug 2024, 16:11

Type Values Removed Values Added
CWE CWE-532
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
References () https://www.realtek.com/images/safe-report/Realtek_RtsPer_RtsUer_Security_Advisory_Report.pdf - () https://www.realtek.com/images/safe-report/Realtek_RtsPer_RtsUer_Security_Advisory_Report.pdf - Vendor Advisory
References () http://realtek.com - () http://realtek.com - Broken Link
References () https://gist.github.com/zwclose/feb16f1424779a61cb1d9f6d5681408a - () https://gist.github.com/zwclose/feb16f1424779a61cb1d9f6d5681408a - Third Party Advisory
First Time Realtek rtsper
Realtek
Realtek rtsuer
CPE cpe:2.3:a:realtek:rtsper:*:*:*:*:*:*:*:*
cpe:2.3:a:realtek:rtsuer:*:*:*:*:*:*:*:*

02 Jul 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-02 19:15

Updated : 2024-10-29 15:35


NVD link : CVE-2022-25477

Mitre link : CVE-2022-25477


JSON object : View

Products Affected

realtek

  • rtsuer
  • rtsper
CWE
CWE-532

Insertion of Sensitive Information into Log File