7.8

CVE-2018-16098

In some Lenovo ThinkPads, an unquoted search path vulnerability was found in various versions of the Synaptics Pointing Device driver which could allow unauthorized code execution as a low privilege user.

Data is provided by the National Vulnerability Database (NVD)
LenovoSynaptics Thinkpad Ultranav Driver Version18.0.7.119
   MicrosoftWindows 7 Version-
   MicrosoftWindows 8.1 Version- SwEditionpro_n
LenovoSynaptics Thinkpad Ultranav Driver Version19.5.19.33
   MicrosoftWindows 10 Version-
LenovoSynaptics Thinkpad Ultranav Driver Version19.0.17.140
   MicrosoftWindows 7 Version-
   MicrosoftWindows 8.1 Version-
LenovoSynaptics Thinkpad Ultranav Driver Version19.3.4.219
   MicrosoftWindows 10 Version-
   MicrosoftWindows 7 Version-
   MicrosoftWindows 8.1 Version-
LenovoSynaptics Thinkpad Ultranav Driver Version16.2.19.23
   MicrosoftWindows 7 Version-
   MicrosoftWindows 8.1 Version-
LenovoSynaptics Thinkpad Ultranav Driver Version18.1.27.42
   MicrosoftWindows 7 Version-
   MicrosoftWindows 8.1 Version-
LenovoThinkpad Helix Firmware Version-
   LenovoThinkpad Helix Version-
LenovoThiankpad L430 Firmware Version-
   LenovoThiankpad L430 Version-
LenovoThiankpad L530 Firmware Version-
   LenovoThiankpad L530 Version-
LenovoThiankpad P1 Firmware Version-
   LenovoThiankpad P1 Version-
LenovoThiankpad P50s Firmware Version-
   LenovoThiankpad P50s Version-
LenovoThiankpad P51 Firmware Version-
   LenovoThiankpad P51 Version-
LenovoThiankpad P51s Firmware Version-
   LenovoThiankpad P51s Version-
LenovoThiankpad P52s Firmware Version-
   LenovoThiankpad P52s Version-
LenovoThiankpad P70 Firmware Version-
   LenovoThiankpad P70 Version-
LenovoThiankpad S1 Yoga Firmware Version-
   LenovoThiankpad S1 Yoga Version-
LenovoThiankpad S430 Firmware Version-
   LenovoThiankpad S430 Version-
LenovoThiankpad T420 Firmware Version-
   LenovoThiankpad T420 Version-
LenovoThiankpad T420i Firmware Version-
   LenovoThiankpad T420i Version-
LenovoThinkpad T420s Firmware Version-
   LenovoThinkpad T420s Version-
LenovoThinkpad T420si Firmware Version-
   LenovoThinkpad T420si Version-
LenovoThinkpad T430s Firmware Version-
   LenovoThinkpad T430s Version-
LenovoThinkpad T430i Firmware Version-
   LenovoThinkpad T430i Version-
LenovoThinkpad T430s Firmware Version-
   LenovoThinkpad T430s Version-
LenovoThinkpad T431s Firmware Version-
   LenovoThinkpad T431s Version-
LenovoThinkpad T440 Firmware Version-
   LenovoThinkpad T440 Version-
LenovoThinkpad T440s Firmware Version-
   LenovoThinkpad T440s Version-
LenovoThinkpad T440p Firmware Version-
   LenovoThinkpad T440p Version-
LenovoThinkpad T460s Firmware Version-
   LenovoThinkpad T460s Version-
LenovoThinkpad T470 Firmware Version-
   LenovoThinkpad T470 Version-
LenovoThinkpad T470s Firmware Version-
   LenovoThinkpad T470s Version-
LenovoThinkpad T430s Firmware Version-
   LenovoThinkpad T430s Version-
LenovoThinkpad T520 Firmware Version-
   LenovoThinkpad T520 Version-
LenovoThinkpad T520i Firmware Version-
   LenovoThinkpad T520i Version-
LenovoThinkpad T530 Firmware Version-
   LenovoThinkpad T530 Version-
LenovoThinkpad T530i Firmware Version-
   LenovoThinkpad T530i Version-
LenovoThinkpad T540 Firmware Version-
   LenovoThinkpad T540 Version-
LenovoThinkpad T540p Firmware Version-
   LenovoThinkpad T540p Version-
LenovoThinkpad T550 Firmware Version-
   LenovoThinkpad T550 Version-
LenovoThinkpad T560 Firmware Version-
   LenovoThinkpad T560 Version-
LenovoThinkpad T570 Firmware Version-
   LenovoThinkpad T570 Version-
LenovoThinkpad T580 Firmware Version-
   LenovoThinkpad T580 Version-
LenovoThinkpad Twist Firmware Version-
   LenovoThinkpad Twist Version-
LenovoThinkpad S230u Firmware Version-
   LenovoThinkpad S230u Version-
LenovoThinkpad W530 Firmware Version-
   LenovoThinkpad W530 Version-
LenovoThinkpad W540 Firmware Version-
   LenovoThinkpad W540 Version-
LenovoThinkpad W541 Firmware Version-
   LenovoThinkpad W541 Version-
LenovoThinkpad W550s Firmware Version-
   LenovoThinkpad W550s Version-
LenovoThinkpad X1 Yoga Firmware Version-
   LenovoThinkpad X1 Yoga Version-
LenovoThinkpad X1 Firmware Version-
   LenovoThinkpad X1 Version-
LenovoThinkpad X220 Firmware Version-
   LenovoThinkpad X220 Version-
LenovoThinkpad X220i Firmware Version-
   LenovoThinkpad X220i Version-
LenovoThinkpad X230 Firmware Version-
   LenovoThinkpad X230 Version-
LenovoThinkpad X230i Firmware Version-
   LenovoThinkpad X230i Version-
LenovoThinkpad X230s Firmware Version-
   LenovoThinkpad X230s Version-
LenovoThinkpad X240s Firmware Version-
   LenovoThinkpad X240s Version-
LenovoThinkpad X240 Firmware Version-
   LenovoThinkpad X240 Version-
LenovoThinkpad X250 Firmware Version-
   LenovoThinkpad X250 Version-
LenovoThinkpad X280 Firmware Version-
   LenovoThinkpad X280 Version-
LenovoThinkpad Yoga 11e Firmware Version-
   LenovoThinkpad Yoga 11e Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.06% 0.139
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-428 Unquoted Search Path or Element

The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.