CVE-2024-40431

A lack of input validation in Realtek SD card reader driver before 10.0.26100.21374 through the implementation of the IOCTL_SCSI_PASS_THROUGH control of the SD card reader driver allows an attacker to write to predictable kernel memory locations, even as a low-privileged user.
Configurations

No configuration.

History

24 Oct 2024, 18:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
Summary
  • (es) La falta de validación de entrada en Realtek SD card reader driver anterior a 10.0.26100.21374 a través de la implementación del control IOCTL_SCSI_PASS_THROUGH del controlador del lector de tarjetas SD permite que un atacante escriba en ubicaciones de memoria del kernel predecibles, incluso como un usuario con pocos privilegios.

23 Oct 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-23 22:15

Updated : 2024-10-25 12:56


NVD link : CVE-2024-40431

Mitre link : CVE-2024-40431

CVE.ORG link : CVE-2024-40431


JSON object : View

Products Affected

No product.

CWE

No CWE.