Attacker Value
Unknown
0
CVE-2018-16098
0
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
Attacker Value
Unknown
(0 users assessed)Exploitability
Unknown
(0 users assessed)User Interaction
Unknown
Privileges Required
Unknown
Attack Vector
Unknown
0
CVE-2018-16098
(Last updated November 27, 2024) ▾
MITRE ATT&CK
Log in to add MITRE ATT&CK tag
Add MITRE ATT&CK tactics and techniques that apply to this CVE.
MITRE ATT&CK
Select the MITRE ATT&CK Tactics that apply to this CVE
Collection
Select any Techniques used:
Command and Control
Select any Techniques used:
Credential Access
Select any Techniques used:
Defense Evasion
Select any Techniques used:
Discovery
Select any Techniques used:
Execution
Select any Techniques used:
Exfiltration
Select any Techniques used:
Impact
Select any Techniques used:
Initial Access
Select any Techniques used:
Lateral Movement
Select any Techniques used:
Persistence
Select any Techniques used:
Privilege Escalation
Select any Techniques used:
Topic Tags
Select the tags that apply to this CVE (Assessment added tags are disabled and cannot be removed)
What makes this of high-value to an attacker?
What makes this of low-value to an attacker?
Description
In some Lenovo ThinkPads, an unquoted search path vulnerability was found in various versions of the Synaptics Pointing Device driver which could allow unauthorized code execution as a low privilege user.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
Data provided by the National Vulnerability Database (NVD)
Base Score:
None
Impact Score:
Unknown
Exploitability Score:
Unknown
Attack Vector (AV):
Unknown
Attack Complexity (AC):
Unknown
Privileges Required (PR):
Unknown
User Interaction (UI):
Unknown
Scope (S):
Unknown
Confidentiality (C):
Unknown
Integrity (I):
Unknown
Availability (A):
Unknown
General Information
Offensive Application
Unknown
Utility Class
Unknown
Ports
Unknown
OS
Unknown
Vulnerable Versions
Various ThinkPad products Various
Prerequisites
Unknown
Discovered By
Unknown
PoC Author
Unknown
Metasploit Module
Unknown
Reporter
Unknown
Vendors
Products
- synaptics thinkpad ultranav driver 16.2.19.23,
- synaptics thinkpad ultranav driver 18.0.7.119,
- synaptics thinkpad ultranav driver 18.1.27.42,
- synaptics thinkpad ultranav driver 19.0.17.140,
- synaptics thinkpad ultranav driver 19.3.4.219,
- synaptics thinkpad ultranav driver 19.5.19.33,
- thiankpad l430 firmware -,
- thiankpad l530 firmware -,
- thiankpad p1 firmware -,
- thiankpad p50s firmware -,
- thiankpad p51 firmware -,
- thiankpad p51s firmware -,
- thiankpad p52s firmware -,
- thiankpad p70 firmware -,
- thiankpad s1 yoga firmware -,
- thiankpad s430 firmware -,
- thiankpad t420 firmware -,
- thiankpad t420i firmware -,
- thiankpad x1 extreme firmware -,
- thinkpad helix firmware -,
- thinkpad s230u firmware -,
- thinkpad t420s firmware -,
- thinkpad t420si firmware -,
- thinkpad t430i firmware -,
- thinkpad t430s firmware -,
- thinkpad t431s firmware -,
- thinkpad t440 firmware -,
- thinkpad t440p firmware -,
- thinkpad t440s firmware -,
- thinkpad t460s firmware -,
- thinkpad t470 firmware -,
- thinkpad t470s firmware -,
- thinkpad t520 firmware -,
- thinkpad t520i firmware -,
- thinkpad t530 firmware -,
- thinkpad t530i firmware -,
- thinkpad t540 firmware -,
- thinkpad t540p firmware -,
- thinkpad t550 firmware -,
- thinkpad t560 firmware -,
- thinkpad t570 firmware -,
- thinkpad t580 firmware -,
- thinkpad twist firmware -,
- thinkpad w530 firmware -,
- thinkpad w540 firmware -,
- thinkpad w541 firmware -,
- thinkpad w550s firmware -,
- thinkpad x1 carbon firmware -,
- thinkpad x1 firmware -,
- thinkpad x1 hybrid firmware -,
- thinkpad x1 yoga firmware -,
- thinkpad x220 firmware -,
- thinkpad x220 tablet firmware -,
- thinkpad x220i firmware -,
- thinkpad x230 firmware -,
- thinkpad x230 tablet firmware -,
- thinkpad x230i firmware -,
- thinkpad x230i tablet firmware -,
- thinkpad x230s firmware -,
- thinkpad x240 firmware -,
- thinkpad x240s firmware -,
- thinkpad x250 firmware -,
- thinkpad x280 firmware -,
- thinkpad yoga 11e firmware -
References
Additional Info
Authenticated
Unknown
Exploitable
Unknown
Reliability
Unknown
Stability
Unknown
Available Mitigations
Unknown
Shelf Life
Unknown
Userbase/Installbase
Unknown
Patch Effectiveness
Unknown
Rapid7
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: