CVE-2019-18619

HIGH

Synaptics WBF <2019-11-15 - RCE

Title source: llm
STIX 2.1

Description

Incorrect parameter validation in the synaTee component of Synaptics WBF drivers using an SGX enclave (all versions prior to 2019-11-15) allows a local user to execute arbitrary code in the enclave (that can compromise confidentiality of enclave data) via APIs that accept invalid pointers.

Scores

CVSS v3 7.8
EPSS 0.0014
EPSS Percentile 33.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-763
Status published
Products (50)
hp/envy_-_13t-ah100_firmware < 5.5.11.1093
hp/envy_-_13t-aq100_firmware < 6.0.39.1111
hp/envy_-_17t-bw000_firmware < 5.5.11.1093
hp/envy_-_17t-ce000_firmware < 6.0.39.1111
hp/envy_-_17t-ce100_firmware < 6.0.39.1111
hp/envy_13-ah0xxx_firmware < 5.5.11.1093
hp/envy_13-ah1xxx_firmware < 5.5.11.1093
hp/envy_13-aq0xxx_firmware < 6.0.39.1111
hp/envy_13-aq1xxx_firmware < 6.0.39.1111
hp/envy_15-cn0xxx_x360_firmware < 5.5.11.1093
... and 40 more
Published Jul 22, 2020
Tracked Since Feb 18, 2026