Home

Description

A carefully crafted DLL, copied to C:\ProgramData\Synaptics folder, allows a local user to execute arbitrary code with elevated privileges during driver installation.

PUBLISHED Reserved 2025-10-14 | Published 2025-12-01 | Updated 2025-12-01 | Assigner Synaptics




MEDIUM: 6.6CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-427 Uncontrolled Search Path Element

Product status

Default status
unaffected

5.5.3521.1066 (custom) before 5.5.3537.1066
affected

5.5.4012.1052 (custom) before 5.5.4022.1052
affected

References

www.synaptics.com/...installer-security-brief-2025-12-01.pdf

cve.org (CVE-2025-11772)

nvd.nist.gov (CVE-2025-11772)

Download JSON