Описание
Realtek NDIS driver rt640x64.sys, file version 10.1.505.2015, fails to do any size checking on an input buffer from user space, which the driver assumes has a size greater than zero bytes. To exploit this vulnerability, an attacker must send an IRP with a system buffer size of 0.
Ссылки
- Third Party Advisory
- Vendor Advisory
- Third Party Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:realtek:ndis:10.1.505.2015:*:*:*:*:*:*:*
EPSS
Процентиль: 32%
0.00122
Низкий
5.5 Medium
CVSS3
2.1 Low
CVSS2
Дефекты
CWE-476
Связанные уязвимости
github
больше 3 лет назад
Realtek NDIS driver rt640x64.sys, file version 10.1.505.2015, fails to do any size checking on an input buffer from user space, which the driver assumes has a size greater than zero bytes. To exploit this vulnerability, an attacker must send an IRP with a system buffer size of 0.
EPSS
Процентиль: 32%
0.00122
Низкий
5.5 Medium
CVSS3
2.1 Low
CVSS2
Дефекты
CWE-476