2024-07-02 20:03:23 +00:00
{
"id" : "CVE-2022-25480" ,
"sourceIdentifier" : "cve@mitre.org" ,
"published" : "2024-07-02T19:15:12.037" ,
2024-12-08 03:06:42 +00:00
"lastModified" : "2024-11-21T06:52:15.070" ,
2024-10-24 18:03:22 +00:00
"vulnStatus" : "Modified" ,
2024-07-02 20:03:23 +00:00
"cveTags" : [ ] ,
"descriptions" : [
{
"lang" : "en" ,
"value" : "Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 allows writing to kernel memory beyond the SystemBuffer of the IRP."
2024-07-03 14:05:06 +00:00
} ,
{
"lang" : "es" ,
"value" : "Una vulnerabilidad en el controlador Realtek RtsPer para lector de tarjetas PCIe (RtsPer.sys) anterior a 10.0.22000.21355 y el controlador Realtek RtsUer para lector de tarjetas USB (RtsUer.sys) anterior a 10.0.22000.31274 permite escribir en la memoria del kernel m\u00e1s all\u00e1 del SystemBuffer del IRP."
2024-07-02 20:03:23 +00:00
}
] ,
2024-08-21 16:03:14 +00:00
"metrics" : {
"cvssMetricV31" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 7.8 ,
"baseSeverity" : "HIGH" ,
2024-08-21 16:03:14 +00:00
"attackVector" : "LOCAL" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "HIGH"
2024-08-21 16:03:14 +00:00
} ,
"exploitabilityScore" : 1.8 ,
"impactScore" : 5.9
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-787"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:realtek:rtsper:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "10.0.22000.21355" ,
"matchCriteriaId" : "126006F2-0655-4EAB-AD95-87AADA0C8F8E"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:realtek:rtsuer:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "10.0.22000.31274" ,
"matchCriteriaId" : "B45E5C60-6DE7-4324-84A0-5F4270C6ACA0"
}
]
}
]
}
] ,
2024-07-02 20:03:23 +00:00
"references" : [
{
"url" : "http://realtek.com" ,
2024-08-21 16:03:14 +00:00
"source" : "cve@mitre.org" ,
"tags" : [
"Broken Link"
]
2024-07-02 20:03:23 +00:00
} ,
{
"url" : "https://gist.github.com/zwclose/feb16f1424779a61cb1d9f6d5681408a" ,
2024-08-21 16:03:14 +00:00
"source" : "cve@mitre.org" ,
"tags" : [
"Third Party Advisory"
]
2024-07-02 20:03:23 +00:00
} ,
{
"url" : "https://www.realtek.com/images/safe-report/Realtek_RtsPer_RtsUer_Security_Advisory_Report.pdf" ,
2024-08-21 16:03:14 +00:00
"source" : "cve@mitre.org" ,
"tags" : [
"Vendor Advisory"
]
2024-10-24 18:03:22 +00:00
} ,
{
"url" : "https://zwclose.github.io/2024/10/14/rtsper1.html" ,
"source" : "cve@mitre.org"
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "http://realtek.com" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Broken Link"
]
} ,
{
"url" : "https://gist.github.com/zwclose/feb16f1424779a61cb1d9f6d5681408a" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Third Party Advisory"
]
} ,
{
"url" : "https://www.realtek.com/images/safe-report/Realtek_RtsPer_RtsUer_Security_Advisory_Report.pdf" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Vendor Advisory"
]
2024-07-02 20:03:23 +00:00
}
]
}