CVE-2025-8301

7.8

Realtek · RTL8811AU

A heap-based buffer overflow in the Realtek RTL8811AU driver allows local attackers to escalate privileges to SYSTEM level.

Executive summary

A heap-based buffer overflow vulnerability in the Realtek RTL8811AU driver facilitates local privilege escalation to SYSTEM privileges for authenticated attackers.

Vulnerability

The flaw exists within the N6CSet_DOT11_CIPHER_DEFAULT_KEY function due to insufficient validation of user-supplied data length before copying to a heap-based buffer. An attacker must possess low-privileged access to the target system to successfully trigger this memory corruption.

Business impact

The ability for a local attacker to escalate privileges to the SYSTEM context poses a severe threat to system integrity and confidentiality. By gaining full administrative control, an attacker can bypass security controls, install persistent backdoors, or exfiltrate sensitive data. Given the CVSS score of 7.8, this high-severity vulnerability represents a significant risk to any environment utilizing the affected driver.

Remediation

Immediate Action: Update the Realtek RTL8811AU driver to the latest version provided by the vendor or the system manufacturer to resolve the buffer overflow.

Proactive Monitoring: Monitor system logs for unusual process execution patterns or unexpected spikes in privilege escalation events that may indicate an attempt to exploit driver-level vulnerabilities.

Compensating Controls: Ensure that the principle of least privilege is strictly enforced on all endpoints to limit the number of users capable of executing the code required to trigger this local vulnerability.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Organizations should prioritize the deployment of updated driver packages to all workstations and servers utilizing the Realtek RTL8811AU hardware. Because this vulnerability allows for complete system compromise from a low-privileged state, patching should be treated as a high-priority maintenance task to prevent local privilege escalation.

More Realtek CVEs

Sources