Record summary

CVE-2022-25478 has a selected CVSS score of 7.8 (high); EIP currently links 1 repository PoC.

Description

Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 provides read and write access to the PCI configuration space of the device.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 5, 2024 · Source: CVE List

Proofs of concept

1

Repository PoCs

GitHubHORKimhab/CVE-2022-25477Repository PoCby HORKimhabStars: 0Not analyzed5 files

3.0 MiB · linked to 6 vulnerabilities

GitHub

PoC details

References

5