Vulnerability Description
An unquoted search path vulnerability was reported in versions prior to 1.0.83.0 of the Synaptics Smart Audio UWP app associated with the DCHU audio drivers on Lenovo platforms that could allow an administrative user to execute arbitrary code.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Synaptics | Smart Audio Uwp | < 1.0.83.0 |
| Lenovo | 5-15Ikb | - |
| Lenovo | Air-14 2019 | - |
| Lenovo | C340-14Iwl | - |
| Lenovo | Flex-14Iwl | - |
| Lenovo | S540-14Iwl | - |
| Lenovo | S540-14Iwl Touch | - |
| Lenovo | Thinkpad 11E | - |
| Lenovo | Thinkpad 13 | - |
| Lenovo | Thinkpad A275 | - |
| Lenovo | Thinkpad A285 | - |
| Lenovo | Thinkpad A475 | - |
| Lenovo | Thinkpad A485 | - |
| Lenovo | Thinkpad E450 | - |
| Lenovo | Thinkpad E450C | - |
| Lenovo | Thinkpad E455 | - |
| Lenovo | Thinkpad E460 | - |
| Lenovo | Thinkpad E465 | - |
| Lenovo | Thinkpad E470 | - |
| Lenovo | Thinkpad E475 | - |
Related Weaknesses (CWE)
References
- https://support.lenovo.com/us/en/product_security/len-30707Vendor Advisory
- https://www.synaptics.com/sites/default/files/audio-driver-security-brief-2020-0Vendor Advisory
- https://support.lenovo.com/us/en/product_security/len-30707Vendor Advisory
- https://www.synaptics.com/sites/default/files/audio-driver-security-brief-2020-0Vendor Advisory
FAQ
What is CVE-2020-8337?
CVE-2020-8337 is a vulnerability with a CVSS score of 6.7 (MEDIUM). An unquoted search path vulnerability was reported in versions prior to 1.0.83.0 of the Synaptics Smart Audio UWP app associated with the DCHU audio drivers on Lenovo platforms that could allow an adm...
How severe is CVE-2020-8337?
CVE-2020-8337 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-8337?
Check the references section above for vendor advisories and patch information. Affected products include: Synaptics Smart Audio Uwp, Lenovo 5-15Ikb, Lenovo Air-14 2019, Lenovo C340-14Iwl, Lenovo Flex-14Iwl.