CVE-2022-25479

MEDIUM

Realtek Rtsper < 10.0.22000.21355 - Memory Leak

Title source: rule
STIX 2.1

Description

Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 allows for the leakage of kernel memory from both the stack and the heap.

Exploits (1)

nomisec WORKING POC 45 stars
by SpiralBL0CK · poc
https://github.com/SpiralBL0CK/CVE-2024-40431-CVE-2022-25479-EOP-CHAIN

Scores

CVSS v3 5.5
EPSS 0.0280
EPSS Percentile 86.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-401
Status published
Products (2)
realtek/rtsper < 10.0.22000.21355
realtek/rtsuer < 10.0.22000.31274
Published Jul 02, 2024
Tracked Since Feb 18, 2026