CVE-2020-8337

MEDIUM

Synaptics Smart Audio <1.0.83.0 - Code Injection

Title source: llm
STIX 2.1

Description

An unquoted search path vulnerability was reported in versions prior to 1.0.83.0 of the Synaptics Smart Audio UWP app associated with the DCHU audio drivers on Lenovo platforms that could allow an administrative user to execute arbitrary code.

References (2)

Core 2

Scores

CVSS v3 6.7
EPSS 0.0038
EPSS Percentile 29.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-428
Status published
Products (1)
synaptics/smart_audio_uwp < 1.0.83.0
Published Jun 09, 2020
Tracked Since Feb 18, 2026