Advisory Details

October 8th, 2020

(0Day) Realtek rtl81xx SDK Wi-Fi Driver rtwlane Out-Of-Bounds Write Remote Code Execution Vulnerability

ZDI-20-1240
ZDI-CAN-10181

CVE ID
CVSS SCORE 7.5, AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
AFFECTED VENDORS Realtek
AFFECTED PRODUCTS rtl81xx SDK
VULNERABILITY DETAILS

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Realtek rtl81xx SDK Wi-Fi driver. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the processing of 802.11 frames. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the kernel.

ADDITIONAL DETAILS

This vulnerability is being disclosed publicly without a patch in accordance with the ZDI 120 day deadline.

05/11/20 - ZDI reported the vulnerability to the vendor
05/13/20 – The vendor confirmed receipt of the report and requested more technical details
05/13/20 - ZDI clarified that the technical details are included in the report
08/18/20 - ZDI contacted the vendor requesting a status update
09/09/20 - ZDI requested an update
10/01/20 - ZDI notified the vendor of the intention to publish these reports as 0-day advisories on 10/08/2020

-- Mitigation:
Given the nature of the vulnerability the only salient mitigation strategy is to restrict interaction with the application.


DISCLOSURE TIMELINE
  • 2020-04-29 - Vulnerability reported to vendor
  • 2020-10-08 - Coordinated public release of advisory
  • 2021-06-29 - Advisory Updated
CREDIT Haikuo Xie ,Ying Wang of Baidu Security Lab
BACK TO ADVISORIES