CVE-2019-18619
Incorrect parameter validation in the synaTee component of Synaptics WBF drivers using an SGX enclave (all versions prior to 2019-11-15) allows a local user to execute arbitrary code in the enclave (that can compromise confidentiality of enclave data)…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.51%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Incorrect parameter validation in the synaTee component of Synaptics WBF drivers using an SGX enclave (all versions prior to 2019-11-15) allows a local user to execute arbitrary code in the enclave (that can compromise confidentiality of enclave data) via APIs that accept invalid pointers.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.51% probability · 42th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-763
- Affected
- synaptics/vfs75xx firmware · lenovo/thinkpad 25 firmware · lenovo/thankpad a475 firmware · lenovo/thankpad a485 firmware · lenovo/thinkpad e480 firmware · lenovo/thinkpad e580 firmware · lenovo/thinkpad e485 firmware · lenovo/thinkpad e585 firmware · lenovo/thinkpad e490s firmware · lenovo/thinkpad s3 firmware · lenovo/thinkpad e490 firmware · lenovo/thinkpad e590 firmware · lenovo/thinkpad r490 firmware · lenovo/thinkpad r590 firmware · lenovo/thinkpad l480 firmware · lenovo/thinkpad l580 firmware · lenovo/thinkpad p1 firmware · lenovo/thinkpad p1 gen 2 firmware · lenovo/thinkpad x1 extreme 2nd firmware · lenovo/thinkpad p43s firmware · +40 more
- Source
- cve@mitre.org
References
- https://support.hp.com/hk-en/document/c06696568Patch, Third Party Advisory
- https://support.lenovo.com/us/en/product_security/LEN-31372Patch, Third Party Advisory
- https://www.synaptics.com/company/blog/Vendor Advisory
- https://www.synaptics.com/sites/default/files/fingerprint-driver-SGX-security-brief-2020-07-14.pdfVendor Advisory
- https://www.syssec.wiwi.uni-due.de/en/research/research-projects/analysis-of-tee-software/Vendor Advisory
- https://support.hp.com/hk-en/document/c06696568Patch, Third Party Advisory
- https://support.lenovo.com/us/en/product_security/LEN-31372Patch, Third Party Advisory
- https://www.synaptics.com/company/blog/Vendor Advisory
- https://www.synaptics.com/sites/default/files/fingerprint-driver-SGX-security-brief-2020-07-14.pdfVendor Advisory
- https://www.syssec.wiwi.uni-due.de/en/research/research-projects/analysis-of-tee-software/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.