Vulnerabilities > CVE-2019-18619 - Release of Invalid Pointer or Reference vulnerability in multiple products

047910
CVSS 4.6 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
local
low complexity
synaptics
lenovo
hp
CWE-763

Summary

Incorrect parameter validation in the synaTee component of Synaptics WBF drivers using an SGX enclave (all versions prior to 2019-11-15) allows a local user to execute arbitrary code in the enclave (that can compromise confidentiality of enclave data) via APIs that accept invalid pointers.

Vulnerable Configurations

Part Description Count
OS
Synaptics
17
OS
Lenovo
68
OS
Hp
43
Hardware
Synaptics
1
Hardware
Lenovo
68
Hardware
Hp
43

Common Weakness Enumeration (CWE)