CVE-2025-11772: Co-Installer Privilege Escalation
Published Dec 1, 2025
·Updated
A carefully crafted DLL, copied to
C:\ProgramData\Synaptics
folder, allows a local user to execute arbitrary code with elevated privileges during driver installation.
Affected Software
1 affected component
Synaptics Synaptics Driver
Event History
Dec 1, 2025
CVE Published
via MITRE·06:55 PM
Data Sourced
via MITRE·06:55 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-11772?
CVE-2025-11772 has a high severity rating due to its potential for remote code execution with elevated privileges.
2
How do I fix CVE-2025-11772?
To fix CVE-2025-11772, ensure that you install the latest version of the Synaptics Driver from the official source.
3
Who is affected by CVE-2025-11772?
CVE-2025-11772 affects users who have the Synaptics Driver installed on their systems.
4
What type of vulnerability is CVE-2025-11772?
CVE-2025-11772 is a local privilege escalation vulnerability that can be exploited by a local user.
5
Can CVE-2025-11772 be exploited remotely?
No, CVE-2025-11772 requires local access to exploit the vulnerability.