CVE-2019-18619
CVE-2019-18619
Incorrect parameter validation in the synaTee component of Synaptics WBF drivers using an SGX enclave (all versions prior to 2019-11-15) allows a local user to execute arbitrary code in the enclave (that can compromise confidentiality of enclave data) via APIs that accept invalid pointers.
Productos afectados
n/a · n/a¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
https://support.hp.com/hk-en/document/c06696568https://support.lenovo.com/us/en/product_security/LEN-31372https://www.synaptics.com/company/blog/https://www.synaptics.com/sites/default/files/fingerprint-driver-SGX-security-brief-2020-07-14.pdfhttps://www.syssec.wiwi.uni-due.de/en/research/research-projects/analysis-of-tee-software/