CVE-2018-16098

UnknownEPSS 0.40%

Last modified

CVE-2018-16098 is a vulnerability of currently unknown severity. In some Lenovo ThinkPads, an unquoted search path vulnerability was found in various versions of the Synaptics Pointing Device driver which could allow unauthorized code execution as a low privilege user.. EPSS estimates a 0.40% chance of exploitation in the next 30 days.

Description

In some Lenovo ThinkPads, an unquoted search path vulnerability was found in various versions of the Synaptics Pointing Device driver which could allow unauthorized code execution as a low privilege user.

Metrics

EPSS Probability
0.40%

31.5th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
LenovoSynaptics Thinkpad Ultranav Driver18.0.7.119
LenovoSynaptics Thinkpad Ultranav Driver19.5.19.33
LenovoSynaptics Thinkpad Ultranav Driver19.0.17.140
LenovoSynaptics Thinkpad Ultranav Driver19.3.4.219
LenovoSynaptics Thinkpad Ultranav Driver16.2.19.23
LenovoSynaptics Thinkpad Ultranav Driver18.1.27.42
LenovoThinkpad Helix FirmwareAll versions
LenovoThiankpad L430 FirmwareAll versions
LenovoThiankpad L530 FirmwareAll versions
LenovoThiankpad P1 FirmwareAll versions
LenovoThiankpad X1 Extreme FirmwareAll versions
LenovoThiankpad P50s FirmwareAll versions
LenovoThiankpad P51 FirmwareAll versions
LenovoThiankpad P51s FirmwareAll versions
LenovoThiankpad P52s FirmwareAll versions
LenovoThiankpad P70 FirmwareAll versions
LenovoThiankpad S1 Yoga FirmwareAll versions
LenovoThiankpad S430 FirmwareAll versions
LenovoThiankpad T420 FirmwareAll versions
LenovoThiankpad T420i FirmwareAll versions
LenovoThinkpad T420s FirmwareAll versions
LenovoThinkpad T420si FirmwareAll versions
LenovoThinkpad T430s FirmwareAll versions
LenovoThinkpad T430i FirmwareAll versions
LenovoThinkpad T431s FirmwareAll versions
LenovoThinkpad T440 FirmwareAll versions
LenovoThinkpad T440s FirmwareAll versions
LenovoThinkpad T440p FirmwareAll versions
LenovoThinkpad T460s FirmwareAll versions
LenovoThinkpad T470 FirmwareAll versions
LenovoThinkpad T470s FirmwareAll versions
LenovoThinkpad T520 FirmwareAll versions
LenovoThinkpad T520i FirmwareAll versions
LenovoThinkpad T530 FirmwareAll versions
LenovoThinkpad T530i FirmwareAll versions
LenovoThinkpad T540 FirmwareAll versions
LenovoThinkpad T540p FirmwareAll versions
LenovoThinkpad T550 FirmwareAll versions
LenovoThinkpad T560 FirmwareAll versions
LenovoThinkpad T570 FirmwareAll versions
LenovoThinkpad T580 FirmwareAll versions
LenovoThinkpad Twist FirmwareAll versions
LenovoThinkpad S230u FirmwareAll versions
LenovoThinkpad W530 FirmwareAll versions
LenovoThinkpad W540 FirmwareAll versions
LenovoThinkpad W541 FirmwareAll versions
LenovoThinkpad W550s FirmwareAll versions
LenovoThinkpad X1 Carbon FirmwareAll versions
LenovoThinkpad X1 Yoga FirmwareAll versions
LenovoThinkpad X1 FirmwareAll versions

Showing 50 of 64 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2018-16098?
In some Lenovo ThinkPads, an unquoted search path vulnerability was found in various versions of the Synaptics Pointing Device driver which could allow unauthorized code execution as a low privilege user.
How severe is CVE-2018-16098?
Severity scoring for CVE-2018-16098 is pending analysis. The EPSS model estimates a 0.40% probability of exploitation in the next 30 days.
How do I fix CVE-2018-16098?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2018-16098?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST