CVE-2021-3675

synaTEE.signed.dll Out-Of-Bounds Heap Write

Description

Improper Input Validation vulnerability in synaTEE.signed.dll of Synaptics Fingerprint Driver allows a local authorized attacker to overwrite a heap tag, with potential loss of confidentiality. This issue affects: Synaptics Synaptics Fingerprint Driver 5.1.xxx.26 versions prior to xxx=340 on x86/64; 5.2.xxxx.26 versions prior to xxxx=3541 on x86/64; 5.2.2xx.26 versions prior to xx=29 on x86/64; 5.2.3xx.26 versions prior to xx=25 on x86/64; 5.3.xxxx.26 versions prior to xxxx=3543 on x86/64; 5.5.xx.1058 versions prior to xx=44 on x86/64; 5.5.xx.1102 versions prior to xx=34 on x86/64; 5.5.xx.1116 versions prior to xx=14 on x86/64; 6.0.xx.1104 versions prior to xx=50 on x86/64; 6.0.xx.1108 versions prior to xx=31 on x86/64; 6.0.xx.1111 versions prior to xx=58 on x86/64.

Remediation

Solution:

  • Listed drivers and above have additional input validation.

Categories

5.5
CVSS
Severity: Medium
CVSS 3.1 •
CVSS 2.0 •
EPSS 0.04%
Vendor Advisory synaptics.com
Affected: Synaptics Synaptics Fingerprint Driver
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2021-3675?
CVE-2021-3675 has been scored as a medium severity vulnerability.
How to fix CVE-2021-3675?
To fix CVE-2021-3675: Listed drivers and above have additional input validation.
Is CVE-2021-3675 being actively exploited in the wild?
As for now, there are no information to confirm that CVE-2021-3675 is being actively exploited. According to its EPSS score, there is a ~0% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2021-3675?
CVE-2021-3675 affects Synaptics Synaptics Fingerprint Driver.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.