CVE-2023-4936

It is possible to sideload a compromised DLL during the installation at elevated privilege.
Configurations

Configuration 1 (hide)

cpe:2.3:a:synaptics:displaylink_usb_graphics:*:*:*:*:*:windows:*:*

History

21 Nov 2024, 08:36

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.8
v2 : unknown
v3 : 5.5
References () https://www.synaptics.com/ - Product () https://www.synaptics.com/ - Product
References () https://www.synaptics.com/products/displaylink-graphics/downloads/windows - Product () https://www.synaptics.com/products/displaylink-graphics/downloads/windows - Product
References () https://www.synaptics.com/sites/default/files/nr-154525-tc-synaptics_displaylink_windows_driver_security_brief_-_oct2023.pdf - Vendor Advisory () https://www.synaptics.com/sites/default/files/nr-154525-tc-synaptics_displaylink_windows_driver_security_brief_-_oct2023.pdf - Vendor Advisory

Information

Published : 2023-10-11 17:15

Updated : 2024-11-21 08:36


NVD link : CVE-2023-4936

Mitre link : CVE-2023-4936

CVE.ORG link : CVE-2023-4936


JSON object : View

Products Affected

synaptics

  • displaylink_usb_graphics
CWE
CWE-269

Improper Privilege Management

CWE-427

Uncontrolled Search Path Element