In some Lenovo ThinkPads, an unquoted search path vulnerability was found in various versions of the Synaptics Pointing Device driver which could allow unauthorized code execution as a low privilege user.
The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.
Link | Tags |
---|---|
https://support.lenovo.com/us/en/solutions/LEN-24573 | broken link |
https://support.lenovo.com/bg/en/product_security/len-24573 | patch vendor advisory |