Vulnerabilities > CVE-2019-18619 - Release of Invalid Pointer or Reference vulnerability in multiple products

047910
CVSS 7.8 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
local
low complexity
synaptics
lenovo
hp
CWE-763

Summary

Incorrect parameter validation in the synaTee component of Synaptics WBF drivers using an SGX enclave (all versions prior to 2019-11-15) allows a local user to execute arbitrary code in the enclave (that can compromise confidentiality of enclave data) via APIs that accept invalid pointers.

Vulnerable Configurations

Part Description Count
OS
Synaptics
17
OS
Lenovo
92
OS
Hp
43
Hardware
Synaptics
1
Hardware
Lenovo
68
Hardware
Hp
43

Common Weakness Enumeration (CWE)