Back to Database
Status published
Medium
CVE-2025-11772
Co-Installer Privilege Escalation
Vulnerability Description
A carefully crafted DLL, copied to C:\ProgramData\Synaptics folder, allows a local user to execute arbitrary code with elevated privileges during driver installation.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-11772
Credits & Attribution
No credits recorded in the NVD database.
More from Synaptics
View All →CVE-2024-9157
Privilege Escalation Vulnerability in CxUIUSvc service
High
7.8
CVE-2023-6482
Encryption key derived from static host information
Medium
5.2
CVE-2023-5447
Use-After-Free in Service for Hardware Support App for Fingerprint Driver
Medium
5.5
CVE-2023-4936
Synaptics-DisplayLink-privilege escalation vulnerability via a dynamic library sideloading
Medium
5.5
CVE-2021-3675
synaTEE.signed.dll Out-Of-Bounds Heap Write
Medium
5.5
Affected Vendor
Synaptics
View all reports →Affected Software
Synaptics Fingerprint Driver
Vulnerable Versions:
5.5.3521.1066, 5.5.4012.1052
Timeline
Official Publish:
December 1st, 2025
Last Modified:
December 1st, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H