← Back to driver explorer
Driver intelligenceVulnerableVerified

RtsPer.sys

The Realtek SD card reader driver, RtsPer.sys, has been found to contain multiple critical vulnerabilities (CVE-2022-25476, CVE-2022-25477, CVE-2022-25478, CVE-2022-25479, CVE-2022-25480, CVE-2024-40431, CVE-2024-40432) that allow non-privileged users to leak kernel memory, write to arbitrary kernel memory, and access physical memory via DMA. These flaws affect various SD card reader models (including RTS5227, RTS5228, RTS522A, RTS5249, RTS524A, RTS5250, RTS525A, RTS5287, RTS5260, RTS5261, RTS5264) used by major OEMs such as Dell, Lenovo, HP, and MSI. The vulnerabilities enable kernel memory leaks, arbitrary kernel memory writes, PCI configuration space manipulation, and DMA controller access from user mode. Due to the driver's widespread use, the impact is significant, potentially allowing privilege escalation and system compromise. Realtek has addressed these issues in driver version 10.0.26100.21374 or higher, released in July or August.

UUID / 32155681-33e8-4d0d-b9f6-c822851e7321ADDED / 2024-09-10AUTHOR / Michael M.

Known samples 1

1 recorded TRUE · 0 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.

RtsPer.sysSample 1 · HVCI TRUE
MD5
807a860e330865e932e17b8a699ff5ea
SHA1
c07c37bab9208dceca35fbe154684ed6c6450e5c
SHA256
a1fa7d8275ccd14a6adc438ef4b950e7de4ed26fcbe4b3e184243663b03c83d6
Imphash
5dfbbdfddea4d6dc325c7c3759fdda18
Authentihash MD5
4873b596b473865c3e1ebbcc31a5420a
Authentihash SHA1
c7425bd2d79ed34c9ec48d04c4a4df05daa8f024
Authentihash SHA256
e060b051d0b8eca8490347f679e63391c792b6b37684e11301f4ed187173c3fd
Machine
ARM64
Version
10.0.26100.21373
Publisher
Realtek Semiconductor Corporation

Recorded command

sc.exe create RtsPer.sys binPath=C:\windows\temp\RtsPer.sys type=kernel && sc.exe start RtsPer.sys

Elevate privileges · Privileges: kernel · OS: Windows 10

Research & references