realtek.com
http://realtek.com/ CVE-2022-25478
HIGH
Record summary
CVE-2022-25478 has a selected CVSS score of 7.8 (high); EIP currently links 1 repository PoC.
Description
Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 provides read and write access to the PCI configuration space of the device.
Description source: CVE List
Exploitation context
Available material
- Repository PoCs
- 1
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 5, 2024 · Source: CVE List
Proofs of concept
1Repository PoCs
GitHubHORKimhab/CVE-2022-25477Repository PoCby HORKimhabStars: 0Not analyzed5 files
References
5gist.github.com
https://gist.github.com/zwclose/feb16f1424779a61cb1d9f6d5681408a nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-25478 realtek.com
https://www.realtek.com/images/safe-report/Realtek_RtsPer_RtsUer_Security_Advisory_Report.pdf zwclose.github.io
https://zwclose.github.io/2024/10/14/rtsper1.html