436
VMScore

CVE-2021-32537

Published: 07/07/2021 Updated: 07/11/2023
CVSS v2 Base Score: 4.9 | Impact Score: 6.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 6.5 | Impact Score: 4 | Exploitability Score: 2
VMScore: 436
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

Realtek HAD contains a driver crashed vulnerability which allows local side malicious users to send a special string to the kernel driver in a user’s mode. Due to unexpected commands, the kernel driver will cause the system crashed.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

realtek hda driver

Github Repositories

PoC for CVE-2021-32537: an out-of-bounds memory access that leads to pool corruption in the Windows kernel.

CVE-2021-32537: Out-of-bounds access in RTKVHD64 leading to pool corruption This is a bug that I reported to Realtek beginning of April 2021 The affected driver is named RTKVHD64sys and seems to be available on a bunch of mainstream hardware (tested the below hardware configurations but probably more are vulnerables): Microsoft Surface Laptop, Microsoft Surface Book, Micros