CVE-2024-40431
HIGH 8.8EPSS 1.3%
A lack of input validation in Realtek SD card reader driver before 10.0.26100.21374 through the implementation of the IOCTL_SCSI_PASS_THROUGH control of the SD card reader driver allows an attacker to write to predictable kernel memory locations, even as a low-privileged user.
- CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS
- 1.26% chance of exploitation in the next 30 days, 68th percentile
- Published
- 2024-10-23
- Updated
- 2024-10-24
Proof-of-concept exploits (2)
- SpiralBL0CK/CVE-2024-40431-CVE-2022-25479-EOP-CHAIN46★ · 2024-10-16
- zwclose/realteksd11★ · 2024-10-14