CVE-2018-16098

In some Lenovo ThinkPads, an unquoted search path vulnerability was found in various versions of the Synaptics Pointing Device driver which could allow unauthorized code execution as a low privilege user.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
lenovoCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 17%
VendorProductVersion
lenovosynaptics_thinkpad_ultranav_driver
18.0.7.119
lenovosynaptics_thinkpad_ultranav_driver
19.5.19.33
lenovosynaptics_thinkpad_ultranav_driver
19.0.17.140
lenovosynaptics_thinkpad_ultranav_driver
19.3.4.219
lenovosynaptics_thinkpad_ultranav_driver
16.2.19.23
lenovosynaptics_thinkpad_ultranav_driver
18.1.27.42
lenovothinkpad_helix_firmware
-
lenovothiankpad_l430_firmware
-
lenovothiankpad_l530_firmware
-
lenovothiankpad_p1_firmware
-
lenovothiankpad_x1_extreme_firmware
-
lenovothiankpad_p50s_firmware
-
lenovothiankpad_p51_firmware
-
lenovothiankpad_p51s_firmware
-
lenovothiankpad_p52s_firmware
-
lenovothiankpad_p70_firmware
-
lenovothiankpad_s1_yoga_firmware
-
lenovothiankpad_s430_firmware
-
lenovothiankpad_t420_firmware
-
lenovothiankpad_t420i_firmware
-
lenovothinkpad_t420s_firmware
-
lenovothinkpad_t420si_firmware
-
lenovothinkpad_t430s_firmware
-
lenovothinkpad_t430i_firmware
-
lenovothinkpad_t430s_firmware
-
lenovothinkpad_t431s_firmware
-
lenovothinkpad_t440_firmware
-
lenovothinkpad_t440s_firmware
-
lenovothinkpad_t440p_firmware
-
lenovothinkpad_t460s_firmware
-
lenovothinkpad_t470_firmware
-
lenovothinkpad_t470s_firmware
-
lenovothinkpad_t430s_firmware
-
lenovothinkpad_t520_firmware
-
lenovothinkpad_t520i_firmware
-
lenovothinkpad_t530_firmware
-
lenovothinkpad_t530i_firmware
-
lenovothinkpad_t540_firmware
-
lenovothinkpad_t540p_firmware
-
lenovothinkpad_t550_firmware
-
lenovothinkpad_t560_firmware
-
lenovothinkpad_t570_firmware
-
lenovothinkpad_t580_firmware
-
lenovothinkpad_twist_firmware
-
lenovothinkpad_s230u_firmware
-
lenovothinkpad_w530_firmware
-
lenovothinkpad_w540_firmware
-
lenovothinkpad_w541_firmware
-
lenovothinkpad_w550s_firmware
-
lenovothinkpad_x1_carbon_firmware
-
lenovothinkpad_x1_yoga_firmware
-
lenovothinkpad_x1_firmware
-
lenovothinkpad_x1_hybrid_firmware
-
lenovothinkpad_x220_firmware
-
lenovothinkpad_x220i_firmware
-
lenovothinkpad_x220_tablet_firmware
-
lenovothinkpad_x230_firmware
-
lenovothinkpad_x230i_firmware
-
lenovothinkpad_x230_tablet_firmware
-
lenovothinkpad_x230i_tablet_firmware
-
lenovothinkpad_x230s_firmware
-
lenovothinkpad_x240s_firmware
-
lenovothinkpad_x240_firmware
-
lenovothinkpad_x250_firmware
-
lenovothinkpad_x280_firmware
-
lenovothinkpad_yoga_11e_firmware
-
𝑥
= Vulnerable software versions