CVE-2019-19705

HIGHCVSS 7.8/10EPSS 0.20%

Last modified

CVE-2019-19705 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Realtek Audio Drivers for Windows, as used on the Lenovo ThinkPad X1 Carbon 20A7, 20A8, 20BS, and 20BT before 6.0.8882.1 and 20KH and 20KG before 6.0.8907.1 (and on many other Lenovo and non-Lenovo products), mishandles DLL preloading.. EPSS estimates a 0.20% chance of exploitation in the next 30 days.

Description

Realtek Audio Drivers for Windows, as used on the Lenovo ThinkPad X1 Carbon 20A7, 20A8, 20BS, and 20BT before 6.0.8882.1 and 20KH and 20KG before 6.0.8907.1 (and on many other Lenovo and non-Lenovo products), mishandles DLL preloading.

Metrics

CVSS 3.1
7.8/10

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS Probability
0.20%

10.5th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
LenovoIdeacentre 510-15ikl Firmware< 6.0.8923.1
LenovoIdeacentre 510s-08ikl Firmware< 6.0.8923.1
LenovoIdeacentre 300s-11ish Firmware< 6.0.8924.1
LenovoIdeacentre 310-15asr Firmware< 6.0.8924.1
LenovoIdeacentre 310-15iap Firmware< 6.0.8924.1
LenovoIdeacentre 310a-15iap Firmware< 6.0.8924.1
LenovoIdeacentre 310s-08iap Firmware< 6.0.8924.1
LenovoIdeacentre 510-15abr Firmware< 6.0.8924.1
LenovoIdeacentre 510s-08ish Firmware< 6.0.8924.1
LenovoIdeacentre 610s-02ish Firmware< 6.0.8924.1
LenovoIdeacentre 620s-03ikl Firmware< 6.0.8924.1
LenovoIdeacentre 700 Firmware< 6.0.8924.1
LenovoIdeacentre 720-18asr Firmware< 6.0.8924.1
LenovoLegion Y520t Z370 Firmware< 6.0.8924.1
LenovoLegion Y720 Tower Firmware< 6.0.8924.1
LenovoLegion Y720t Amd Firmware< 6.0.8924.1
LenovoLegion Y920 Tower Firmware< 6.0.8924.1
LenovoLenovo V320-15iap Firmware< 6.0.8924.1
LenovoThinkcentre E74s Firmware< 6.0.8924.1
LenovoYangtian Mc H110 Firmware< 6.0.8924.1
LenovoYangtian Me\/We H110 Firmware< 6.0.8924.1
LenovoYangtian Tc\/Wc H110 Pci Firmware< 6.0.8924.1
LenovoYangtian Ytm6900e-00 Firmware< 6.0.8924.1
LenovoYta8900f Firmware< 6.0.8924.1
LenovoThinkcentre M6600 Firmware< 6.0.8924.1
LenovoThinkcentre M6600q Firmware< 6.0.8924.1
LenovoThinkcentre M6600t\/S Firmware< 6.0.8924.1
LenovoThinkcentre M700q Firmware< 6.0.8924.1
LenovoThinkcentre M700t\/S Firmware< 6.0.8924.1
LenovoThinkcentre M710e Firmware< 6.0.8924.1
LenovoThinkcentre M710q Firmware< 6.0.8924.1
LenovoThinkcentre M710t\/S Firmware< 6.0.8924.1
LenovoThinkcentre M715q Firmware< 6.0.8924.1
LenovoThinkcentre M715t\/S Firmware< 6.0.8924.1
LenovoThinkcentre M800 Firmware< 6.0.8924.1
LenovoThinkcentre M8600t\/S Firmware< 6.0.8924.1
LenovoThinkcentre M900 Firmware< 6.0.8924.1
LenovoThinkcentre M910 T\/S Firmware< 6.0.8924.1
LenovoThinkcentre M910q Firmware< 6.0.8924.1
LenovoThinkcentre M910x Firmware< 6.0.8924.1
LenovoYangtian Afh110 Firmware< 6.0.8924.1
LenovoYangtian Afq150 Firmware< 6.0.8924.1
LenovoYangtian Mc H110 Pci Firmware< 6.0.8924.1
LenovoYangtian Mf\/Wf H110 Pci Firmware< 6.0.8924.1
LenovoAio 910-27ish Firmware< 6.0.8924.1
LenovoAio Y910-27ish Firmware< 6.0.8881.1
LenovoAio300-23isu Firmware< 6.0.8881.1
LenovoAio310-20iap Firmware< 6.0.8881.1
LenovoAio510-22ish Firmware< 6.0.8881.1
LenovoAio510-23ish Firmware< 6.0.8881.1

Showing 50 of 138 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-19705?
Realtek Audio Drivers for Windows, as used on the Lenovo ThinkPad X1 Carbon 20A7, 20A8, 20BS, and 20BT before 6.0.8882.1 and 20KH and 20KG before 6.0.8907.1 (and on many other Lenovo and non-Lenovo products), mishandles DLL preloading.
How severe is CVE-2019-19705?
CVE-2019-19705 has a CVSS score of 7.8/10 (HIGH severity). The EPSS model estimates a 0.20% probability of exploitation in the next 30 days.
How do I fix CVE-2019-19705?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-19705?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST