RtsPer.sys
The Realtek SD card reader driver, RtsPer.sys, has been found to contain multiple critical vulnerabilities (CVE-2022-25476, CVE-2022-25477, CVE-2022-25478, CVE-2022-25479, CVE-2022-25480, CVE-2024-40431, CVE-2024-40432) that allow non-privileged users to leak kernel memory, write to arbitrary kernel memory, and access physical memory via DMA. These flaws affect various SD card reader models (including RTS5227, RTS5228, RTS522A, RTS5249, RTS524A, RTS5250, RTS525A, RTS5287, RTS5260, RTS5261, RTS5264) used by major OEMs such as Dell, Lenovo, HP, and MSI. The vulnerabilities enable kernel memory leaks, arbitrary kernel memory writes, PCI configuration space manipulation, and DMA controller access from user mode. Due to the driver's widespread use, the impact is significant, potentially allowing privilege escalation and system compromise. Realtek has addressed these issues in driver version 10.0.26100.21374 or higher, released in July or August.
Known samples 1
1 recorded TRUE · 0 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.
RtsPer.sysSample 1 · HVCI TRUE
- MD5
807a860e330865e932e17b8a699ff5ea- SHA1
c07c37bab9208dceca35fbe154684ed6c6450e5c- SHA256
a1fa7d8275ccd14a6adc438ef4b950e7de4ed26fcbe4b3e184243663b03c83d6- Imphash
5dfbbdfddea4d6dc325c7c3759fdda18- Authentihash MD5
4873b596b473865c3e1ebbcc31a5420a- Authentihash SHA1
c7425bd2d79ed34c9ec48d04c4a4df05daa8f024- Authentihash SHA256
e060b051d0b8eca8490347f679e63391c792b6b37684e11301f4ed187173c3fd- Machine
- ARM64
- Version
- 10.0.26100.21373
- Publisher
- Realtek Semiconductor Corporation
Recorded command
sc.exe create RtsPer.sys binPath=C:\windows\temp\RtsPer.sys type=kernel && sc.exe start RtsPer.sysElevate privileges · Privileges: kernel · OS: Windows 10

