7.8
CVSSv3

CVE-2019-18619

Published: 22/07/2020 Updated: 30/07/2020
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Incorrect parameter validation in the synaTee component of Synaptics WBF drivers using an SGX enclave (all versions before 2019-11-15) allows a local user to execute arbitrary code in the enclave (that can compromise confidentiality of enclave data) via APIs that accept invalid pointers.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

synaptics vfs75xx firmware 5.2.225.26

synaptics vfs75xx firmware 5.2.318.26

synaptics vfs75xx firmware 5.2.524.26

synaptics vfs75xx firmware 5.2.3530.26

synaptics vfs75xx firmware 5.3.3539.26

synaptics vfs75xx firmware 5.5.3.1116

synaptics vfs75xx firmware 5.5.8.1096

synaptics vfs75xx firmware 5.5.10.1093

synaptics vfs75xx firmware 5.5.11.1106

synaptics vfs75xx firmware 5.5.15.1102

synaptics vfs75xx firmware 5.5.38.1058

synaptics vfs75xx firmware 5.5.2734.1050

synaptics vfs75xx firmware 5.5.2811.1050

synaptics vfs75xx firmware 5.6.23.1000

synaptics vfs75xx firmware 6.0.14.1108

synaptics vfs75xx firmware 6.0.32.1104

synaptics vfs75xx firmware 6.0.42.1107

lenovo thinkpad 25 firmware

lenovo thankpad a475 firmware

lenovo thankpad a485 firmware

lenovo thinkpad e480 firmware

lenovo thinkpad e580 firmware

lenovo thinkpad e485 firmware

lenovo thinkpad e585 firmware

lenovo thinkpad e490s firmware

lenovo thinkpad s3 firmware

lenovo thinkpad e490 firmware

lenovo thinkpad e590 firmware

lenovo thinkpad r490 firmware

lenovo thinkpad r590 firmware

lenovo thinkpad l480 firmware

lenovo thinkpad l580 firmware

lenovo thinkpad p1 firmware

lenovo thinkpad p1 gen 2 firmware

lenovo thinkpad x1 extreme 2nd firmware

lenovo thinkpad p43s firmware

lenovo thinkpad p50 firmware

lenovo thinkpad p51 firmware

lenovo thinkpad p51s (20jx) firmware

lenovo thinkpad p51s (20kx) firmware

lenovo thinkpad p51s (20hx) firmware

lenovo thinkpad p52 firmware

lenovo thinkpad p52s firmware

lenovo thinkpad p53 firmware

lenovo thinkpad p53s firmware

lenovo thinkpad p70 firmware

lenovo thinkpad p71 (20hx) firmware

lenovo thinkpad p72 firmware

lenovo thinkpad p73 firmware

lenovo thinkpad t25 (20k7) firmware

lenovo thinkpad t460p firmware

lenovo thinkpad t460s firmware

lenovo thinkpad t470 (20hx) firmware

lenovo thinkpad t470 (20jx) firmware

lenovo thinkpad t470p firmware

lenovo thinkpad t470s (20hx) firmware

lenovo thinkpad t470s (20jx) firmware

lenovo thinkpad t480 firmware

lenovo thinkpad t480s firmware

lenovo thinkpad t490 firmware

lenovo thinkpad t490s firmware

lenovo thinkpad t570 (20hx) firmware

lenovo thinkpad t570(20jx) firmware

lenovo thinkpad t580 firmware

lenovo thinkpad t590 firmware

lenovo thinkpad x1 carbon (20hx) firmware

lenovo thinkpad x1 carbon (20kx) firmware

lenovo thinkpad x1 carbon firmware

lenovo thinkpad x1 yoga 4th gen firmware

lenovo thinkpad x1 extreme firmware

lenovo thinkpad x1 tablet firmware

lenovo thinkpad x1 tablet (20jx) firmware

lenovo thinkpad x1 yoga firmware

lenovo thinkpad x1 yoga (20jx) firmware

lenovo thinkpad x1 yoga 3rd gen firmware

lenovo thinkpad x270 firmware

lenovo thinkpad x280 firmware

lenovo thinkpad x380 yoga firmware

lenovo thinkpad x390 firmware

lenovo thinkpad x390 yoga firmware

lenovo thinkpad yoga 370 firmware

lenovo thinkpad s1 3rd firmware

lenovo thinkpad yoga 260 firmware

lenovo thinkpad yoga s1 firmware

lenovo thinkpad a275 firmware

hp envy - 13t-ah100 firmware

hp envy - 13t-aq100 firmware

hp envy 13-ah0xxx firmware

hp envy 13-ah1xxx firmware

hp envy 13-aq0xxx firmware

hp envy 13-aq1xxx firmware

hp envy - 17t-bw000 firmware

hp envy - 17t-ce000 firmware

hp envy - 17t-ce100 firmware

hp envy 17-bw0xxx firmware

hp envy 17-ce0xxx firmware

hp envy 17-ce1xxx firmware

hp envy 17m-bw0xxx firmware

hp envy 17m-ce0xxx firmware

hp envy 17m-ce1xxx firmware

hp envy x360 - 15t-cn000 firmware

hp envy x360 - 15t-dr000 firmware

hp envy x360 - 15t-dr000 (validity fps) firmware

hp envy x360 - 15t-dr100 firmware

hp envy x360 - 15t-dr100 (validity fps) firmware

hp envy 15-cn0xxx x360 firmware

hp envy 15-cn1xxx x360 firmware

hp envy 15-dr0xxx x360 firmware

hp envy 15-dr0xxx x360 (validity fps) firmware

hp envy 15-dr1xxx x360 firmware

hp envy 15-dr1xxx x360 (validity fps) firmware

hp envy 15m-cn0xxx x360 firmware

hp envy 15m-dr0xxx x360 firmware

hp envy 15m-dr0xxx x360 (validity fps) firmware

hp envy 15m-dr1xxx x360 firmware

hp envy 15m-dr1xxx x360 (validity fps) firmware

hp pavilion x360 - 14t-cd000 firmware

hp pavilion x360 - 15t-dq000 firmware

hp pavilion x360 - 15t-dq100 firmware

hp pavilion x360 14t-cd100 firmware

hp pavilion x360 14t-dh000 firmware

hp pavilion 14-cd1xxx x360 firmware

hp pavilion 14-cd2xxx x360 firmware

hp pavilion 14-dh0xxx x360 firmware

hp pavilion 14m-cd0xxx x360 firmware

hp pavilion 14m-dh0xxx x360 firmware

hp pavilion 15 firmware

hp spectre x360 firmware

Vendor Advisories

Synaptics has notified HP of a potential security vulnerability in certain versions of Synaptics Fingerprint Sensor Drivers using Intel® Software Guard eXtensions (SGX), which may allow a local user to execute arbitrary code that can compromise confidentiality of the Synaptics SGX protected memory The Synaptics Security Brief for this vulner ...
Synaptics has notified HP of a potential security vulnerability in certain versions of Synaptics Fingerprint Sensor Drivers using Intel® Software Guard eXtensions (SGX), which may allow a local user to execute arbitrary code that can compromise confidentiality of the Synaptics SGX protected memory The Synaptics Security Brief for this vulner ...

Github Repositories

PoC exploits against various SGX enclaves

TeeRex SGX Exploits This repository contains several exploits that we developed in the course of our research on memory corruption bugs in SGX enclaves The full results of our research are published at USENIX Security 2020 Project Vulnerable Version Exploit Comment Intel GMP Demo 9533574 Intel SGX GMP Demo Exploit ✔️ Fixed Rust SGX SDK TLSClient v109 Rust TLSCl