Attacker Value
Unknown
0
CVE-2019-19705
0
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
CVE-2019-19705
(Last updated October 08, 2023) ▾
MITRE ATT&CK
Log in to add MITRE ATT&CK tag
Add MITRE ATT&CK tactics and techniques that apply to this CVE.
MITRE ATT&CK
Select the MITRE ATT&CK Tactics that apply to this CVE
Collection
Select any Techniques used:
Command and Control
Select any Techniques used:
Credential Access
Select any Techniques used:
Defense Evasion
Select any Techniques used:
Discovery
Select any Techniques used:
Execution
Select any Techniques used:
Exfiltration
Select any Techniques used:
Impact
Select any Techniques used:
Initial Access
Select any Techniques used:
Lateral Movement
Select any Techniques used:
Persistence
Select any Techniques used:
Privilege Escalation
Select any Techniques used:
Topic Tags
Select the tags that apply to this CVE (Assessment added tags are disabled and cannot be removed)
What makes this of high-value to an attacker?
What makes this of low-value to an attacker?
Description
Realtek Audio Drivers for Windows, as used on the Lenovo ThinkPad X1 Carbon 20A7, 20A8, 20BS, and 20BT before 6.0.8882.1 and 20KH and 20KG before 6.0.8907.1 (and on many other Lenovo and non-Lenovo products), mishandles DLL preloading.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
Data provided by the National Vulnerability Database (NVD)
Base Score:
7.8 High
Impact Score:
5.9
Exploitability Score:
1.8
Attack Vector (AV):
Local
Attack Complexity (AC):
Low
Privileges Required (PR):
None
User Interaction (UI):
Required
Scope (S):
Unchanged
Confidentiality (C):
High
Integrity (I):
High
Availability (A):
High
General Information
Offensive Application
Unknown
Utility Class
Unknown
Ports
Unknown
OS
Unknown
Vulnerable Versions
n/a
Prerequisites
Unknown
Discovered By
Unknown
PoC Author
Unknown
Metasploit Module
Unknown
Reporter
Unknown
Vendors
Products
- aio 910 27ish firmware
- aio y910 27ish firmware
- aio300 23isu firmware
- aio310 20iap firmware
- aio510 22ish firmware
- aio510 23ish firmware
- aio520 22ikl firmware
- aio520 22iku firmware
- aio520 24ikl firmware
- aio520 24iku firmware
- aio520 27ikl firmware
- aio720 24ikb firmware
- ideacentre 300s 11ish firmware
- ideacentre 310 15asr firmware
- ideacentre 310 15iap firmware
- ideacentre 310a 15iap firmware
- ideacentre 310s 08iap firmware
- ideacentre 510 15abr firmware
- ideacentre 510 15ikl firmware
- ideacentre 510s 08ikl firmware
- ideacentre 510s 08ish firmware
- ideacentre 520s 23iku firmware
- ideacentre 610s 02ish firmware
- ideacentre 620s 03ikl firmware
- ideacentre 700 firmware
- ideacentre 720 18asr firmware
- legion y520t z370 firmware
- legion y720 tower firmware
- legion y720t amd firmware
- legion y920 tower firmware
- lenovo v320 15iap firmware
- qt a7400 firmware
- sydney e3 h110 firmware
- thinkcentre e74s firmware
- thinkcentre e74z firmware
- thinkcentre e95z firmware
- thinkcentre m6600 firmware
- thinkcentre m6600q firmware
- thinkcentre m6600t/s firmware
- thinkcentre m700q firmware
- thinkcentre m700t/s firmware
- thinkcentre m700z firmware
- thinkcentre m710e firmware
- thinkcentre m710q firmware
- thinkcentre m710t/s firmware
- thinkcentre m715q firmware
- thinkcentre m715t/s firmware
- thinkcentre m7300z firmware
- thinkcentre m800 firmware
- thinkcentre m800z firmware
- thinkcentre m810z firmware
- thinkcentre m818z firmware
- thinkcentre m8300z firmware
- thinkcentre m8350z firmware
- thinkcentre m8600t/s firmware
- thinkcentre m900 firmware
- thinkcentre m900z firmware
- thinkcentre m910 t/s firmware
- thinkcentre m910q firmware
- thinkcentre m910x firmware
- thinkcentre m910z firmware
- thinkcentre m9500z firmware
- thinkcentre m9550z firmware
- thinkcentre x1 aio firmware
- thinkpad 13 firmware
- thinkpad a275 firmware
- thinkpad a475 firmware
- thinkpad l13 yoga firmware
- thinkpad l380 firmware
- thinkpad l380 yoga firmware
- thinkpad l390 yoga firmware
- thinkpad l450 firmware
- thinkpad l460 firmware
- thinkpad l470 firmware
- thinkpad l480 firmware
- thinkpad l560 firmware
- thinkpad l570 firmware
- thinkpad l580 firmware
- thinkpad p50 firmware
- thinkpad p50s firmware
- thinkpad p51 firmware
- thinkpad p51s firmware
- thinkpad p52s firmware
- thinkpad p70 firmware
- thinkpad p71 firmware
- thinkpad s2 yoga 3rd gen firmware
- thinkpad s2 yoga 4th gen firmware
- thinkpad s3 3rd gen firmware
- thinkpad t25 firmware
- thinkpad t450 firmware
- thinkpad t450s firmware
- thinkpad t460 firmware
- thinkpad t460p firmware
- thinkpad t460s firmware
- thinkpad t470 firmware
- thinkpad t470p firmware
- thinkpad t470s firmware
- thinkpad t480 firmware
- thinkpad t480s firmware
- thinkpad t560 firmware
- thinkpad t570 firmware
- thinkpad t580 firmware
- thinkpad x1 carbon firmware
- thinkpad x1 tablet firmware
- thinkpad x1 yoga firmware
- thinkpad x250 firmware
- thinkpad x260 firmware
- thinkpad x270 firmware
- thinkpad x280 firmware
- thinkpad yoga 11e 3rd gen firmware
- thinkpad yoga 11e 4th gen firmware
- thinkserver ts140 firmware
- thinkserver ts150 firmware
- thinkserver ts240 firmware
- thinkserver ts250 firmware
- thinkserver ts450 firmware
- thinkserver ts550 firmware
- thinkstation p310 firmware
- thinkstation p318 firmware
- thinkstation p320 firmware
- thinkstation p320 tiny firmware
- thinkstation p330 firmware
- thinkstation p330 tiny firmware
- v310z(yt s3150) firmware
- v410z(yt s4250) firmware
- v510z (yt s5250) firmware
- yangtian afh110 firmware
- yangtian afq150 firmware
- yangtian mc h110 firmware
- yangtian mc h110 pci firmware
- yangtian me/we h110 firmware
- yangtian mf/wf h110 pci firmware
- yangtian s4150 firmware
- yangtian tc/wc h110 pci firmware
- yangtian ytm6900e 00 firmware
- yta8900f firmware
References
Additional Info
Authenticated
Unknown
Exploitable
Unknown
Reliability
Unknown
Stability
Unknown
Available Mitigations
Unknown
Shelf Life
Unknown
Userbase/Installbase
Unknown
Patch Effectiveness
Unknown
Rapid7
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: