CVE-2025-8302

8.8

Realtek · rtl81xx SDK

A heap-based buffer overflow in the Realtek rtl81xx SDK Wi-Fi driver allows local attackers to escalate privileges to SYSTEM level.

Executive summary

A heap-based buffer overflow vulnerability in the Realtek rtl81xx SDK Wi-Fi driver enables low-privileged local attackers to achieve full system compromise.

Vulnerability

This is a heap-based buffer overflow (CWE-122) occurring within the N6CSet_DOT11_CIPHER_DEFAULT_KEY function. The vulnerability requires an attacker to already have low-privileged code execution on the target system to trigger the overflow and execute arbitrary code as SYSTEM.

Business impact

The ability for a local attacker to escalate privileges to the SYSTEM context represents a critical security failure, as it bypasses all OS-level access controls. With a CVSS score of 8.8, this vulnerability poses a severe risk of complete system takeover, potential data theft, and the installation of persistent malicious backdoors.

Remediation

Immediate Action: Since a specific patch version is not currently identified, users should contact their hardware or device manufacturer to obtain the latest firmware or driver updates containing the fix for ZDI-25-879.

Proactive Monitoring: Monitor system logs for unusual process execution patterns or unauthorized attempts to access sensitive driver-related system functions.

Compensating Controls: Implement strict principle of least privilege policies to ensure that standard users lack the necessary permissions to interface with low-level hardware drivers.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the potential for total system compromise, organizations should prioritize auditing their hardware inventory to identify systems running the affected Realtek rtl81xx SDK. Contact your vendors immediately to verify if an updated driver version has been released to mitigate this heap overflow, and restrict user access to environments where such drivers are deployed until remediation can be verified.

More Realtek CVEs

Sources