CVE-2022-25477

MEDIUM

Realtek Rtsper < 10.0.22000.21355 - Log Information Exposure

Title source: rule
STIX 2.1

Description

Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 leaks driver logs that contain addresses of kernel mode objects, weakening KASLR.

Scores

CVSS v3 5.5
EPSS 0.0014
EPSS Percentile 34.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-532
Status published
Products (2)
realtek/rtsper < 10.0.22000.21355
realtek/rtsuer < 10.0.22000.31274
Published Jul 02, 2024
Tracked Since Feb 18, 2026