Vulnerability Description
RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users to achieve unauthorized access to USB device privileged IN and OUT instructions (leading to Escalation of Privileges, Denial of Service, Code Execution, and Information Disclosure) via a crafted Device IO Control packet to a device.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Realtek | Rtsupx Usb Utility Driver | <= 1.14.0.0 |
References
- https://www.realtek.com/images/safe-report/Realtek_RtsUpx_Security_Advisory_RepoVendor Advisory
- https://www.sentinelone.com/resources/category/report/Not Applicable
- https://www.realtek.com/images/safe-report/Realtek_RtsUpx_Security_Advisory_RepoVendor Advisory
- https://www.sentinelone.com/resources/category/report/Not Applicable
FAQ
What is CVE-2021-36923?
CVE-2021-36923 is a vulnerability with a CVSS score of 7.8 (HIGH). RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users to achieve unauthorized access to USB device privileged IN and OUT instructions ...
How severe is CVE-2021-36923?
CVE-2021-36923 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-36923?
Check the references section above for vendor advisories and patch information. Affected products include: Realtek Rtsupx Usb Utility Driver.