ZeroHour

CVE-2019-18619

CVSS 3.1
7.8 high
EPSS
<1%p42
Published
()
Modified
Description

Incorrect parameter validation in the synaTee component of Synaptics WBF drivers using an SGX enclave (all versions prior to 2019-11-15) allows a local user to execute arbitrary code in the enclave (that can compromise confidentiality of enclave data) via APIs that accept invalid pointers.

Vendors
synapticslenovohp
Products
vfs75xx firmware, thinkpad 25 firmware, thankpad a475 firmware, thankpad a485 firmware, thinkpad e480 firmware, thinkpad e580 firmware, thinkpad e485 firmware, thinkpad e585 firmware, thinkpad e490s firmware, thinkpad s3 firmware, thinkpad e490 firmware, thinkpad e590 firmware
Weakness
CWE-763
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.