SB2019012428 - Information disclosure in Synaptics TouchPad
Published: January 24, 2019 Updated: February 1, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Information disclosure (CVE-ID: CVE-2018-15532)
The vulnerability allows a local attacker to gain access to potentially sensitive information.
The vulnerability exists due to invalidly formatted API requests can cause SynTP.sys to reveal freed kernel memory pointers.. A local attacker can read portions of kernel memory that can be used to weaken KASLR and gain elevated privileges.
Remediation
Install update from vendor's website.