First published: Thu Jun 16 2022(Updated: )
Improper Input Validation vulnerability in synaTEE.signed.dll of Synaptics Fingerprint Driver allows a local authorized attacker to overwrite a heap tag, with potential loss of confidentiality. This issue affects: Synaptics Synaptics Fingerprint Driver 5.1.xxx.26 versions prior to xxx=340 on x86/64; 5.2.xxxx.26 versions prior to xxxx=3541 on x86/64; 5.2.2xx.26 versions prior to xx=29 on x86/64; 5.2.3xx.26 versions prior to xx=25 on x86/64; 5.3.xxxx.26 versions prior to xxxx=3543 on x86/64; 5.5.xx.1058 versions prior to xx=44 on x86/64; 5.5.xx.1102 versions prior to xx=34 on x86/64; 5.5.xx.1116 versions prior to xx=14 on x86/64; 6.0.xx.1104 versions prior to xx=50 on x86/64; 6.0.xx.1108 versions prior to xx=31 on x86/64; 6.0.xx.1111 versions prior to xx=58 on x86/64.
Credit: PSIRT@synaptics.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synaptics Fingerprint Driver | >=5.1.000.26<5.1.340.26 | |
Synaptics Fingerprint Driver | >=5.2.0000.26<5.2.3541.26 | |
Synaptics Fingerprint Driver | >=5.2.200.26<5.2.229.26 | |
Synaptics Fingerprint Driver | >=5.2.300.26<5.2.325.26 | |
Synaptics Fingerprint Driver | >=5.3.0000.26<5.3.3543.26 | |
Synaptics Fingerprint Driver | >=5.5.00.1058<5.5.44.1058 | |
Synaptics Fingerprint Driver | >=5.5.00.1102<5.5.34.1102 | |
Synaptics Fingerprint Driver | >=5.5.00.1116<5.5.14.1116 | |
Synaptics Fingerprint Driver | >=6.0.00.1111<6.0.58.1111 |
Listed drivers and above have additional input validation.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-3675.
The title of the vulnerability is Improper Input Validation vulnerability in synaTEE.signed.dll of Synaptics Fingerprint Driver allows…
The vulnerability allows a local authorized attacker to overwrite a heap tag by exploiting an improper input validation issue in synaTEE.signed.dll of Synaptics Fingerprint Driver.
The severity of CVE-2021-3675 is high with a severity value of 7.1.
The affected software versions are Synaptics Fingerprint Driver 5.1.xxx.26 versions prior to xxx=340 on x86/64, 5.2.xxx.26 versions prior to xxx=3541, 5.2.xxx.26 versions prior to xxx=229, 5.2.xxx.26 versions prior to xxx=325, 5.3.xxx.26 versions prior to xxx=3543, 5.5.44.1058, 5.5.34.1102, 5.5.14.1116, and 6.0.58.1111.
You can find more information about CVE-2021-3675 in the following references: [https://support.hp.com/us-en/document/ish_6411153-6411191-16/hpsbhf03797](https://support.hp.com/us-en/document/ish_6411153-6411191-16/hpsbhf03797), [https://support.lenovo.com/us/en/product_security/LEN-68054](https://support.lenovo.com/us/en/product_security/LEN-68054), [https://synaptics.com/sites/default/files/2022-06/fingerprint-driver-SGX-security-brief-2022-06-14.pdf](https://synaptics.com/sites/default/files/2022-06/fingerprint-driver-SGX-security-brief-2022-06-14.pdf).