4.6
CVSSv2

CVE-2019-18619

Published: 22/07/2020 Updated: 30/07/2020
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Incorrect parameter validation in the synaTee component of Synaptics WBF drivers using an SGX enclave (all versions before 2019-11-15) allows a local user to execute arbitrary code in the enclave (that can compromise confidentiality of enclave data) via APIs that accept invalid pointers.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

synaptics vfs75xx_firmware 5.2.225.26

synaptics vfs75xx_firmware 5.2.318.26

synaptics vfs75xx_firmware 5.2.524.26

synaptics vfs75xx_firmware 5.2.3530.26

synaptics vfs75xx_firmware 5.3.3539.26

synaptics vfs75xx_firmware 5.5.3.1116

synaptics vfs75xx_firmware 5.5.8.1096

synaptics vfs75xx_firmware 5.5.10.1093

synaptics vfs75xx_firmware 5.5.11.1106

synaptics vfs75xx_firmware 5.5.15.1102

synaptics vfs75xx_firmware 5.5.38.1058

synaptics vfs75xx_firmware 5.5.2734.1050

synaptics vfs75xx_firmware 5.5.2811.1050

synaptics vfs75xx_firmware 5.6.23.1000

synaptics vfs75xx_firmware 6.0.14.1108

synaptics vfs75xx_firmware 6.0.32.1104

synaptics vfs75xx_firmware 6.0.42.1107

lenovo thinkpad_25_firmware

lenovo thankpad_a475_firmware

lenovo thankpad_a485_firmware

lenovo thinkpad_e480_firmware

lenovo thinkpad_e580_firmware

lenovo thinkpad_e485_firmware

lenovo thinkpad_e585_firmware

lenovo thinkpad_e490s_firmware

lenovo thinkpad_s3_firmware

lenovo thinkpad_e490_firmware

lenovo thinkpad_e590_firmware

lenovo thinkpad_r490_firmware

lenovo thinkpad_r590_firmware

lenovo thinkpad_l480_firmware

lenovo thinkpad_l580_firmware

lenovo thinkpad_p1_firmware

lenovo thinkpad_p1_gen_2_firmware

lenovo thinkpad_x1_extreme_2nd_firmware

lenovo thinkpad_p43s_firmware

lenovo thinkpad_p50_firmware

lenovo thinkpad_p51_firmware

lenovo thinkpad_p51s_\\(20jx\\)_firmware

lenovo thinkpad_p51s_\\(20kx\\)_firmware

lenovo thinkpad_p51s_\\(20hx\\)_firmware

lenovo thinkpad_p52_firmware

lenovo thinkpad_p52s_firmware

lenovo thinkpad_p53_firmware

lenovo thinkpad_p53s_firmware

lenovo thinkpad_p70_firmware

lenovo thinkpad_p71_\\(20hx\\)_firmware

lenovo thinkpad_p72_firmware

lenovo thinkpad_p73_firmware

lenovo thinkpad_t25_\\(20k7\\)_firmware

lenovo thinkpad_t460p_firmware

lenovo thinkpad_t460s_firmware

lenovo thinkpad_t470_\\(20hx\\)_firmware

lenovo thinkpad_t470_\\(20jx\\)_firmware

lenovo thinkpad_t470p_firmware

lenovo thinkpad_t470s_\\(20hx\\)_firmware

lenovo thinkpad_t470s_\\(20jx\\)_firmware

lenovo thinkpad_t480_firmware

lenovo thinkpad_t480s_firmware

lenovo thinkpad_t490_firmware

lenovo thinkpad_t490s_firmware

lenovo thinkpad_t570_\\(20hx\\)_firmware

lenovo thinkpad_t570\\(20jx\\)_firmware

lenovo thinkpad_t580_firmware

lenovo thinkpad_t590_firmware

lenovo thinkpad_x1_carbon_\\(20hx\\)_firmware

lenovo thinkpad_x1_carbon_\\(20kx\\)_firmware

lenovo thinkpad_x1_carbon_firmware

lenovo thinkpad_x1_yoga_4th_gen_firmware

lenovo thinkpad_x1_extreme_firmware

lenovo thinkpad_x1_tablet_firmware

lenovo thinkpad_x1_tablet_\\(20jx\\)_firmware

lenovo thinkpad_x1_yoga_firmware

lenovo thinkpad_x1_yoga_\\(20jx\\)_firmware

lenovo thinkpad_x1_yoga_3rd_gen_firmware

lenovo thinkpad_x270_firmware

lenovo thinkpad_x280_firmware

lenovo thinkpad_x380_yoga_firmware

lenovo thinkpad_x390_firmware

lenovo thinkpad_x390_yoga_firmware

lenovo thinkpad_yoga_370_firmware

lenovo thinkpad_s1_3rd_firmware

lenovo thinkpad_yoga_260_firmware

lenovo thinkpad_yoga_s1_firmware

lenovo thinkpad_a275_firmware

hp envy_-_13t-ah100_firmware

hp envy_-_13t-aq100_firmware

hp envy_13-ah0xxx_firmware

hp envy_13-ah1xxx_firmware

hp envy_13-aq0xxx_firmware

hp envy_13-aq1xxx_firmware

hp envy_-_17t-bw000_firmware

hp envy_-_17t-ce000_firmware

hp envy_-_17t-ce100_firmware

hp envy_17-bw0xxx_firmware

hp envy_17-ce0xxx_firmware

hp envy_17-ce1xxx_firmware

hp envy_17m-bw0xxx_firmware

hp envy_17m-ce0xxx_firmware

hp envy_17m-ce1xxx_firmware

hp envy_x360_-_15t-cn000_firmware

hp envy_x360_-_15t-dr000_firmware

hp envy_x360_-_15t-dr000_\\(validity_fps\\)_firmware

hp envy_x360_-_15t-dr100_firmware

hp envy_x360_-_15t-dr100_\\(validity_fps\\)_firmware

hp envy_15-cn0xxx_x360_firmware

hp envy_15-cn1xxx_x360_firmware

hp envy_15-dr0xxx_x360_firmware

hp envy_15-dr0xxx_x360_\\(validity_fps\\)_firmware

hp envy_15-dr1xxx_x360_firmware

hp envy_15-dr1xxx_x360_\\(validity_fps\\)_firmware

hp envy_15m-cn0xxx_x360_firmware

hp envy_15m-dr0xxx_x360_firmware

hp envy_15m-dr0xxx_x360_\\(validity_fps\\)_firmware

hp envy_15m-dr1xxx_x360_firmware

hp envy_15m-dr1xxx_x360_\\(validity_fps\\)_firmware

hp pavilion_x360_-_14t-cd000_firmware

hp pavilion_x360_-_15t-dq000_firmware

hp pavilion_x360_-_15t-dq100_firmware

hp pavilion_x360_14t-cd100_firmware

hp pavilion_x360_14t-dh000_firmware

hp pavilion_14-cd1xxx_x360_firmware

hp pavilion_14-cd2xxx_x360_firmware

hp pavilion_14-dh0xxx_x360_firmware

hp pavilion_14m-cd0xxx_x360_firmware

hp pavilion_14m-dh0xxx_x360_firmware

hp pavilion_15_firmware

hp spectre_x360_firmware

Vendor Advisories

Synaptics has notified HP of a potential security vulnerability in certain versions of Synaptics Fingerprint Sensor Drivers using Intel® Software Guard eXtensions (SGX), which may allow a local user to execute arbitrary code that can compromise confidentiality of the Synaptics SGX protected memory The Synaptics Security Brief for this vulner ...
Synaptics has notified HP of a potential security vulnerability in certain versions of Synaptics Fingerprint Sensor Drivers using Intel® Software Guard eXtensions (SGX), which may allow a local user to execute arbitrary code that can compromise confidentiality of the Synaptics SGX protected memory The Synaptics Security Brief for this vulner ...

Github Repositories

PoC exploits against various SGX enclaves

TeeRex SGX Exploits This repository contains several exploits that we developed in the course of our research on memory corruption bugs in SGX enclaves The full results of our research are published at USENIX Security 2020 Project Vulnerable Version Exploit Comment Intel GMP Demo 9533574 Intel SGX GMP Demo Exploit ✔️ Fixed Rust SGX SDK TLSClient v109 Rust TLSCl