HIGH · 7.8

CVE-2018-16098

In some Lenovo ThinkPads, an unquoted search path vulnerability was found in various versions of the Synaptics Pointing Device driver which could allow unauthorized code execution as a low privilege u...

Vulnerability Description

In some Lenovo ThinkPads, an unquoted search path vulnerability was found in various versions of the Synaptics Pointing Device driver which could allow unauthorized code execution as a low privilege user.

CVSS Score

7.8

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
LenovoSynaptics Thinkpad Ultranav Driver18.0.7.119
MicrosoftWindows 7-
MicrosoftWindows 8.1-
MicrosoftWindows 10-
LenovoThinkpad Helix Firmware-
LenovoThinkpad Helix-
LenovoThiankpad L430 Firmware-
LenovoThiankpad L430-
LenovoThiankpad L530 Firmware-
LenovoThiankpad L530-
LenovoThiankpad P1 Firmware-
LenovoThiankpad P1-
LenovoThiankpad X1 Extreme Firmware-
LenovoThiankpad X1 Extreme-
LenovoThiankpad P50S Firmware-
LenovoThiankpad P50S-
LenovoThiankpad P51 Firmware-
LenovoThiankpad P51-
LenovoThiankpad P51S Firmware-
LenovoThiankpad P51S-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-16098?

CVE-2018-16098 is a vulnerability with a CVSS score of 7.8 (HIGH). In some Lenovo ThinkPads, an unquoted search path vulnerability was found in various versions of the Synaptics Pointing Device driver which could allow unauthorized code execution as a low privilege u...

How severe is CVE-2018-16098?

CVE-2018-16098 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-16098?

Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Synaptics Thinkpad Ultranav Driver, Microsoft Windows 7, Microsoft Windows 8.1, Microsoft Windows 10, Lenovo Thinkpad Helix Firmware.