CVE-2021-3675
synaTEE.signed.dll Out-Of-Bounds Heap Write
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Improper Input Validation vulnerability in synaTEE.signed.dll of Synaptics Fingerprint Driver allows a local authorized attacker to overwrite a heap tag, with potential loss of confidentiality. This issue affects: Synaptics Synaptics Fingerprint Driver 5.1.xxx.26 versions prior to xxx=340 on x86/64; 5.2.xxxx.26 versions prior to xxxx=3541 on x86/64; 5.2.2xx.26 versions prior to xx=29 on x86/64; 5.2.3xx.26 versions prior to xx=25 on x86/64; 5.3.xxxx.26 versions prior to xxxx=3543 on x86/64; 5.5.xx.1058 versions prior to xx=44 on x86/64; 5.5.xx.1102 versions prior to xx=34 on x86/64; 5.5.xx.1116 versions prior to xx=14 on x86/64; 6.0.xx.1104 versions prior to xx=50 on x86/64; 6.0.xx.1108 versions prior to xx=31 on x86/64; 6.0.xx.1111 versions prior to xx=58 on x86/64.
Una vulnerabilidad de comprobaciĆ³n de entrada inapropiada en el archivo synaTEE.signed.dll de Synaptics Fingerprint Driver, permite a un atacante local autorizado sobrescribir una etiqueta de la pila, con posible pĆ©rdida de confidencialidad. Este problema afecta a: Synaptics Fingerprint Driver versiones: 5.1.xxx.26 versiones anteriores a xxx=340 en x86/64; 5.2.xxxx.26 versiones anteriores a xxxx=3541 en x86/64; 5.2.2xx.26 versiones anteriores a xx=29 en x86/64; 5.2.3xx.26 versiones anteriores a xx=25 en x86/64; 5.3.xxxx.26 versiones anteriores a xxxx=3543 en x86/64; 5.5.xx.1058 versiones anteriores a xx=44 en x86/64; 5.5.xx.1102 versiones anteriores a xx=34 en x86/64; 5.5.xx.1116 versiones anteriores a xx=14 en x86/64; 6.0.xx.1104 versiones anteriores a xx=50 en x86/64; 6.0.xx.1108 versiones anteriores a xx=31 en x86/64; 6.0.xx.1111 versiones anteriores a xx=58 en x86/64
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-08-02 CVE Reserved
- 2022-06-16 CVE Published
- 2023-03-08 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
- CWE-787: Out-of-bounds Write
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://support.lenovo.com/us/en/product_security/LEN-68054 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://support.hp.com/us-en/document/ish_6411153-6411191-16/hpsbhf03797 | 2023-06-26 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Synaptics Search vendor "Synaptics" | Fingerprint Driver Search vendor "Synaptics" for product "Fingerprint Driver" | >= 5.1.000.26 < 5.1.340.26 Search vendor "Synaptics" for product "Fingerprint Driver" and version " >= 5.1.000.26 < 5.1.340.26" | - |
Affected
| ||||||
Synaptics Search vendor "Synaptics" | Fingerprint Driver Search vendor "Synaptics" for product "Fingerprint Driver" | >= 5.2.0000.26 < 5.2.3541.26 Search vendor "Synaptics" for product "Fingerprint Driver" and version " >= 5.2.0000.26 < 5.2.3541.26" | - |
Affected
| ||||||
Synaptics Search vendor "Synaptics" | Fingerprint Driver Search vendor "Synaptics" for product "Fingerprint Driver" | >= 5.2.200.26 < 5.2.229.26 Search vendor "Synaptics" for product "Fingerprint Driver" and version " >= 5.2.200.26 < 5.2.229.26" | - |
Affected
| ||||||
Synaptics Search vendor "Synaptics" | Fingerprint Driver Search vendor "Synaptics" for product "Fingerprint Driver" | >= 5.2.300.26 < 5.2.325.26 Search vendor "Synaptics" for product "Fingerprint Driver" and version " >= 5.2.300.26 < 5.2.325.26" | - |
Affected
| ||||||
Synaptics Search vendor "Synaptics" | Fingerprint Driver Search vendor "Synaptics" for product "Fingerprint Driver" | >= 5.3.0000.26 < 5.3.3543.26 Search vendor "Synaptics" for product "Fingerprint Driver" and version " >= 5.3.0000.26 < 5.3.3543.26" | - |
Affected
| ||||||
Synaptics Search vendor "Synaptics" | Fingerprint Driver Search vendor "Synaptics" for product "Fingerprint Driver" | >= 5.5.00.1058 < 5.5.44.1058 Search vendor "Synaptics" for product "Fingerprint Driver" and version " >= 5.5.00.1058 < 5.5.44.1058" | - |
Affected
| ||||||
Synaptics Search vendor "Synaptics" | Fingerprint Driver Search vendor "Synaptics" for product "Fingerprint Driver" | >= 5.5.00.1102 < 5.5.34.1102 Search vendor "Synaptics" for product "Fingerprint Driver" and version " >= 5.5.00.1102 < 5.5.34.1102" | - |
Affected
| ||||||
Synaptics Search vendor "Synaptics" | Fingerprint Driver Search vendor "Synaptics" for product "Fingerprint Driver" | >= 5.5.00.1116 < 5.5.14.1116 Search vendor "Synaptics" for product "Fingerprint Driver" and version " >= 5.5.00.1116 < 5.5.14.1116" | - |
Affected
| ||||||
Synaptics Search vendor "Synaptics" | Fingerprint Driver Search vendor "Synaptics" for product "Fingerprint Driver" | >= 6.0.00.1111 < 6.0.58.1111 Search vendor "Synaptics" for product "Fingerprint Driver" and version " >= 6.0.00.1111 < 6.0.58.1111" | - |
Affected
|