Re: New Realtek HD Audio Drivers (ver. 1.91 22 April 2008)
"MowGreen [MVP]" <mowgreen@nowandzen.com> wrote in message
news:#Oaa3cYpIHA.3568@TK2MSFTNGP04.phx.gbl...
> And now, for the bad news:
>
>> Realtek HD Audio Codec Drivers (Vista) - Local Privilege Escalation
>>
>>
>> :: Non-Technical Description
>>
>> Realtek HD Audio Codec Drivers are prone to a local privilege escalation
>> due to insufficient validation of user-mode buffers. Successful
>> exploitation grants SYSTEM privileges to authenticated users, no special
>> privileges are required to exploit the flaw.
>>
>> A malicious attacker can take advantage of these flaws to elevate
>> privileges in the following forms:
>>
>> 1. Creating, reading or writing arbitrary registry keys.
>> 2. Overwriting arbitrary kernel addresses.
>>
>>
>> :: Files affected
>>
>> RTKVHDA.sys < 6.0.1.5605 (32-bit) Windows Vista
>> RTKVHDA64.sys (signed) < 6.0.1.5605 (64-bit) Windows Vista
>>
>> :: Credits
>>
>> Vulnerability discovered and researched by Ruben Santamarta.
>>
>> :: Disclosure Timeline
>>
>> 04/02/2008 - Realtek contacted
>> 04/23/2008 - Flaw fixed. Public Disclosure.
>>
>> :: Technical details - Original Advisory
>>
>> http://www.wintercore.com/advisories/advisory_W010408.html
>>
>
> RTKVHDA.sys and RTKVHDA64.sys V.6.0.1.5605 are in that updated driver
> package. Did they post a Disclaimer for the vulnerability ?
>
> Caveat emptor !
While not related to this particular issue, there are a couple of other
issues to be aware of here too. Loading Logitech's SetPoint software will
sometimes break the driver. A driver reinstall will fix this issue. Also,
for those that run SAM Broadcaster, the last version of the Realtek drivers
will sometimes kill the output. SAM must be completely uninstalled, and
reinstalled from scratch. Would pretty much advise that unless the update
fixes issues that are currently being experienced to stay with what is
working.
--
Sanity calms, but madness is more interesting.
http://www.lockergnome.com/darksentinel
Undo the munge to reply by email
> Cal Bear '66 wrote:
>
>> New Realtek HD Audio Drivers (ver. 1.91 22 April 2008):
>>
>>
>> http://www.realtek.com.tw/downloads...=24&Level=4&Conn=3&DownTypeID=3&GetDown=false
>>
>>
>> Add/Fix
>> 1.) Driver :
>> 1. Fix DTM 1.2 KS topology test fail issue.
>> 2. Customizations.
>>
>>
>> NOTE: There is now a disclaimer before you can download the drivers
>> that it is best to obtain new drivers from your computer/motherboard
>> manufacturer since they may have made customizations to their hardware;
>> although, I personally have never had a problem with the drivers
>> downloaded directly from the Realtek site.
>>
>>
>> I Bleed Blue and Gold
>> GO BEARS!
>>
>>
>>