CVE-2022-25477

MEDIUM

Realtek RtsPer < 10.0.22000.21355 and RtsUer < 10.0.22000.31274 - Kernel Address Leak via Driver Logs

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2022-25477. PoCs published by HORKimhab.

AI-analyzed exploit summary This repository claims to be a PoC for CVE-2022-25477 but contains no actual exploit code, technical details, or vulnerability analysis. It only includes setup instructions, a license, and a README with generic disclaimers and external references.

Description

Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 leaks driver logs that contain addresses of kernel mode objects, weakening KASLR.

Exploits (1)

nomisec STUB
by HORKimhab · poc
https://github.com/HORKimhab/CVE-2022-25477

This repository claims to be a PoC for CVE-2022-25477 but contains no actual exploit code, technical details, or vulnerability analysis. It only includes setup instructions, a license, and a README with generic disclaimers and external references.

Classification
Stub 95%
No auth needed
mistral-large-3 · analyzed Jul 16, 2026 Full analysis →

Scores

CVSS v3 5.5
EPSS 0.0021
EPSS Percentile 11.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-532
Status published
Products (2)
realtek/rtsper < 10.0.22000.21355
realtek/rtsuer < 10.0.22000.31274
Published Jul 02, 2024
Tracked Since Feb 18, 2026