CVE-2022-25478
Last modified
CVE-2022-25478 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 provides read and write access to the PCI configuration space of the device.. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 provides read and write access to the PCI configuration space of the device.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Realtek | Rtsper | < 10.0.22000.21355 |
| Realtek | Rtsuer | < 10.0.22000.31274 |
References
- http://realtek.comBroken Link
- https://gist.github.com/zwclose/feb16f1424779a61cb1d9f6d5681408aThird Party Advisory
- http://realtek.comBroken Link
- https://gist.github.com/zwclose/feb16f1424779a61cb1d9f6d5681408aThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-25478?
How severe is CVE-2022-25478?
How do I fix CVE-2022-25478?
Are you affected by CVE-2022-25478?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
