CVE-2024-33225
Last modified
CVE-2024-33225 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. An issue in the component RTKVHD64.sys of Realtek Semiconductor Corp Realtek(r) High Definition Audio Function Driver v6.0.9549.1 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.. EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
An issue in the component RTKVHD64.sys of Realtek Semiconductor Corp Realtek(r) High Definition Audio Function Driver v6.0.9549.1 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-33225?
How severe is CVE-2024-33225?
How do I fix CVE-2024-33225?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-3322A path traversal vulnerability exists in the 'cyber_security…9.8
- CVE-2024-33220An issue in the component AslO3_64.sys of ASUSTeK Computer I…8.8
- CVE-2024-33221An issue in the component AsusBSItf.sys of ASUSTeK Computer …7.8
- CVE-2024-33222An issue in the component ATSZIO64.sys of ASUSTeK Computer I…8.4
- CVE-2024-33223An issue in the component IOMap64.sys of ASUSTeK Computer In…8.8
- CVE-2024-33224An issue in the component rtkio64.sys of Realtek Semiconduct…8.4
- CVE-2024-33226An issue in the component Access64.sys of Wistron Corporatio…9.9
- CVE-2024-33227An issue in the component ddcdrv.sys of Nicomsoft WinI2C/DDC…8.8
- CVE-2024-33228An issue in the component segwindrvx64.sys of Insyde Softwar…8.4
- CVE-2024-3323Cross Site Scripting in UI Request/Response Validation i…8.3
- CVE-2024-33231Cross Site Scripting vulnerability in Ferozo Email version 1…5.4
- CVE-2024-33247Sourcecodester Employee Task Management System v1.0 is vulne…8.8
Are you affected by CVE-2024-33225?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
