Impact
Realtek Audio Service 1.0.0.55 exposes an unquoted service path vulnerability in RtkAudioService64.exe. The flaw allows a local attacker to place a malicious executable in the directory referenced by the service path, which is then run with LocalSystem privileges during service startup or a system reboot. This results in arbitrary code execution with the highest local privileges, enabling full control over the affected system.
Affected Systems
The vulnerability is confined to Realtek Audio Service released by Realtek in version 1.0.0.55. No additional vendor or product variations are listed as affected.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting no confirmed widespread exploitation. However, the attack is local in nature and requires an attacker who can write to the service directory, which is a realistic scenario on systems where local users have disk write access or where the directory is not protected.
OpenCVE Enrichment