CVE-2019-18619

HIGH

Synaptics VFS75xx Firmware - Use-After-Free via Invalid Pointer in synaTee Component

Title source: llm
STIX 2.1

Description

Incorrect parameter validation in the synaTee component of Synaptics WBF drivers using an SGX enclave (all versions prior to 2019-11-15) allows a local user to execute arbitrary code in the enclave (that can compromise confidentiality of enclave data) via APIs that accept invalid pointers.

References (5)

Core 5

Scores

CVSS v3 7.8
EPSS 0.0047
EPSS Percentile 36.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-763
Status published
Products (50)
hp/envy_-_13t-ah100_firmware < 5.5.11.1093
hp/envy_-_13t-aq100_firmware < 6.0.39.1111
hp/envy_-_17t-bw000_firmware < 5.5.11.1093
hp/envy_-_17t-ce000_firmware < 6.0.39.1111
hp/envy_-_17t-ce100_firmware < 6.0.39.1111
hp/envy_13-ah0xxx_firmware < 5.5.11.1093
hp/envy_13-ah1xxx_firmware < 5.5.11.1093
hp/envy_13-aq0xxx_firmware < 6.0.39.1111
hp/envy_13-aq1xxx_firmware < 6.0.39.1111
hp/envy_15-cn0xxx_x360_firmware < 5.5.11.1093
... and 40 more
Published Jul 22, 2020
Tracked Since Feb 18, 2026