VulnerabilityModified
CVE-2020-8337
An unquoted search path vulnerability was reported in versions prior to 1.0.83.0 of the Synaptics Smart Audio UWP app associated with the DCHU audio drivers on Lenovo platforms that could allow an administrative user to execute arbitrary code.
MEDIUM 6.7EPSS 0.38%
Does this matter?
Lower severity and a low EPSS score (0.38%). Track it; it rarely justifies an emergency change on its own.
Description
An unquoted search path vulnerability was reported in versions prior to 1.0.83.0 of the Synaptics Smart Audio UWP app associated with the DCHU audio drivers on Lenovo platforms that could allow an administrative user to execute arbitrary code.
- CVSS 3.1
- 6.7 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.38% probability · 31th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-428
- Affected
- synaptics/smart audio uwp
- Source
- psirt@lenovo.com
References
- https://support.lenovo.com/us/en/product_security/len-30707Vendor Advisory
- https://www.synaptics.com/sites/default/files/audio-driver-security-brief-2020-06-09.pdfVendor Advisory
- https://support.lenovo.com/us/en/product_security/len-30707Vendor Advisory
- https://www.synaptics.com/sites/default/files/audio-driver-security-brief-2020-06-09.pdfVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.