CVE-2021-3675 - CVE House
Back to Database
Status published Medium CVE-2021-3675

synaTEE.signed.dll Out-Of-Bounds Heap Write

Vulnerability Description

Improper Input Validation vulnerability in synaTEE.signed.dll of Synaptics Fingerprint Driver allows a local authorized attacker to overwrite a heap tag, with potential loss of confidentiality. This issue affects: Synaptics Synaptics Fingerprint Driver 5.1.xxx.26 versions prior to xxx=340 on x86/64; 5.2.xxxx.26 versions prior to xxxx=3541 on x86/64; 5.2.2xx.26 versions prior to xx=29 on x86/64; 5.2.3xx.26 versions prior to xx=25 on x86/64; 5.3.xxxx.26 versions prior to xxxx=3543 on x86/64; 5.5.xx.1058 versions prior to xx=44 on x86/64; 5.5.xx.1102 versions prior to xx=34 on x86/64; 5.5.xx.1116 versions prior to xx=14 on x86/64; 6.0.xx.1104 versions prior to xx=50 on x86/64; 6.0.xx.1108 versions prior to xx=31 on x86/64; 6.0.xx.1111 versions prior to xx=58 on x86/64.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-3675

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Synaptics would like to thank Tobias Cloosters and Johannes Willbold for reporting this issue.

Affected Vendor

Affected Software

Synaptics Fingerprint Driver
Vulnerable Versions:
5.1.xxx.26, 5.2.xxxx.26, 5.2.2xx.26, 5.2.3xx.26, 5.3.xxxx.26, 5.5.xx.1058, 5.5.xx.1102, 5.5.xx.1116, 6.0.xx.1104, 6.0.xx.1108, 6.0.xx.1111

Timeline

Official Publish: June 16th, 2022
Last Modified: September 16th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Weaknesses (CWE)