ID

VAR-202003-1805


CVE

CVE-2019-19705


TITLE

plural  Lenovo  Vulnerability with unquoted search paths or elements in the product

Trust: 0.8

sources: JVNDB: JVNDB-2020-017572

DESCRIPTION

Realtek Audio Drivers for Windows, as used on the Lenovo ThinkPad X1 Carbon 20A7, 20A8, 20BS, and 20BT before 6.0.8882.1 and 20KH and 20KG before 6.0.8907.1 (and on many other Lenovo and non-Lenovo products), mishandles DLL preloading. plural Lenovo The product contains an unquoted search path or element vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. Multiple Lenovo products could allow a local malicious user to execute arbitrary code on the system, caused by a DLL preloading issue in Realtek Audio Drivers. By placing a specially crafted file, an attacker could exploit this vulnerability to execute arbitrary ode on the system

Trust: 1.71

sources: NVD: CVE-2019-19705 // JVNDB: JVNDB-2020-017572 // VULMON: CVE-2019-19705

AFFECTED PRODUCTS

vendor:lenovomodel:thinkstation p318scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkcentre e95zscope:ltversion:6.0.8881.1

Trust: 1.0

vendor:lenovomodel:thinkpad a475scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkpad s2 yoga 3rd genscope:ltversion:6.0.8882.1

Trust: 1.0

vendor:lenovomodel:thinkpad x1 tabletscope:ltversion:6.0.8907.1

Trust: 1.0

vendor:lenovomodel:v410z\scope:ltversion:6.0.8881.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m710qscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkpad t470scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m800scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkstation p320scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkpad yoga 11e 3rd genscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:ideacentre 510-15iklscope:ltversion:6.0.8923.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m710t\/sscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:ideacentre 310-15asrscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m8300zscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m8350zscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkpad 13scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkpad l480scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkpad l570scope:ltversion:6.0.8899.1

Trust: 1.0

vendor:lenovomodel:aio300-23isuscope:ltversion:6.0.8881.1

Trust: 1.0

vendor:lenovomodel:qt a7400scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkpad t25scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkpad p51sscope:ltversion:6.0.8882.1

Trust: 1.0

vendor:lenovomodel:aio520-24ikuscope:ltversion:6.0.8881.1

Trust: 1.0

vendor:lenovomodel:ideacentre 310a-15iapscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:aio510-22ishscope:ltversion:6.0.8881.1

Trust: 1.0

vendor:lenovomodel:yangtian afh110scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:legion y720t amdscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m910zscope:ltversion:6.0.8881.1

Trust: 1.0

vendor:lenovomodel:thinkserver ts140scope:ltversion:6.0.1.7016

Trust: 1.0

vendor:lenovomodel:thinkcentre m9550zscope:ltversion:6.0.8881.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m910xscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m8600t\/sscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m910qscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkpad l380 yogascope:ltversion:6.0.8882.1

Trust: 1.0

vendor:lenovomodel:yangtian mc h110 pciscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkpad l380scope:ltversion:6.0.8882.1

Trust: 1.0

vendor:lenovomodel:sydney e3 h110scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:ideacentre 700scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkpad t470pscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkpad l580scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkserver ts240scope:ltversion:6.0.1.7016

Trust: 1.0

vendor:lenovomodel:yangtian s4150scope:ltversion:6.0.8881.1

Trust: 1.0

vendor:lenovomodel:thinkpad t460scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m6600qscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:legion y920 towerscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m810zscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m700t\/sscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkstation p310scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m700zscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkpad t480scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkpad x1 yogascope:ltversion:6.0.8882.1

Trust: 1.0

vendor:lenovomodel:thinkpad p52sscope:ltversion:6.0.8882.1

Trust: 1.0

vendor:lenovomodel:ideacentre 520s-23ikuscope:ltversion:6.0.8881.1

Trust: 1.0

vendor:lenovomodel:thinkpad l560scope:ltversion:6.0.8899.1

Trust: 1.0

vendor:lenovomodel:ideacentre 310s-08iapscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:v320-15iapscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkpad s2 yoga 4th genscope:ltversion:6.0.8757.1

Trust: 1.0

vendor:lenovomodel:thinkpad t470sscope:ltversion:6.0.8777.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m910 t\/sscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:aio 910-27ishscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkpad x260scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkpad x270scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:legion y520t z370scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkpad x1 carbonscope:ltversion:6.0.8907.1

Trust: 1.0

vendor:lenovomodel:v310z\scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkserver ts450scope:ltversion:6.0.1.7525

Trust: 1.0

vendor:lenovomodel:aio520-24iklscope:ltversion:6.0.8881.1

Trust: 1.0

vendor:lenovomodel:yangtian me\/we h110scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:ideacentre 510s-08iklscope:ltversion:6.0.8923.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m6600scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkcentre e74zscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkpad s3 3rd genscope:ltversion:6.0.8882.1

Trust: 1.0

vendor:lenovomodel:thinkpad x280scope:ltversion:6.0.8882.1

Trust: 1.0

vendor:lenovomodel:aio520-22iklscope:ltversion:6.0.8881.1

Trust: 1.0

vendor:lenovomodel:thinkpad p71scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:aio720-24ikbscope:ltversion:6.0.8881.1

Trust: 1.0

vendor:lenovomodel:yangtian mf\/wf h110 pciscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m900zscope:ltversion:6.0.8881.1

Trust: 1.0

vendor:lenovomodel:thinkpad l450scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m900scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:ideacentre 620s-03iklscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkstation p330scope:ltversion:6.0.8923.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m800zscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkserver ts150scope:ltversion:6.0.1.7525

Trust: 1.0

vendor:lenovomodel:legion y720 towerscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:aio y910-27ishscope:ltversion:6.0.8881.1

Trust: 1.0

vendor:lenovomodel:thinkpad l460scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:ideacentre 310-15iapscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:yangtian mc h110scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:aio310-20iapscope:ltversion:6.0.8881.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m715qscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:aio520-22ikuscope:ltversion:6.0.8881.1

Trust: 1.0

vendor:lenovomodel:ideacentre 510-15abrscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkcentre x1 aioscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m818zscope:ltversion:6.0.8881.1

Trust: 1.0

vendor:lenovomodel:thinkpad a275scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkpad l470scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkpad x250scope:ltversion:6.0.8882.1

Trust: 1.0

vendor:lenovomodel:thinkstation p320 tinyscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkstation p330 tinyscope:ltversion:6.0.8923.1

Trust: 1.0

vendor:lenovomodel:ideacentre 300s-11ishscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkserver ts550scope:ltversion:6.0.1.7525

Trust: 1.0

vendor:lenovomodel:thinkpad x1 carbonscope:ltversion:6.0.8882.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m710escope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkcentre e74sscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkpad p70scope:ltversion:6.0.8882.1

Trust: 1.0

vendor:lenovomodel:yta8900fscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkpad p50scope:ltversion:6.0.8882.1

Trust: 1.0

vendor:lenovomodel:thinkpad t560scope:ltversion:6.0.8882.1

Trust: 1.0

vendor:lenovomodel:thinkpad t450sscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:ideacentre 510s-08ishscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:yangtian tc\/wc h110 pciscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m700qscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:aio520-27iklscope:ltversion:6.0.8881.1

Trust: 1.0

vendor:lenovomodel:thinkserver ts250scope:ltversion:6.0.1.7525

Trust: 1.0

vendor:lenovomodel:thinkpad yoga 11e 4th genscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkpad p50sscope:ltversion:6.0.8882.1

Trust: 1.0

vendor:lenovomodel:thinkpad t480sscope:ltversion:6.0.8907.1

Trust: 1.0

vendor:lenovomodel:yangtian afq150scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkpad l13 yogascope:ltversion:9.0.280.80

Trust: 1.0

vendor:lenovomodel:thinkpad t570scope:ltversion:6.0.8882.1

Trust: 1.0

vendor:lenovomodel:thinkpad x1 tabletscope:ltversion:6.0.8882.1

Trust: 1.0

vendor:lenovomodel:ideacentre 720-18asrscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:aio510-23ishscope:ltversion:6.0.8881.1

Trust: 1.0

vendor:lenovomodel:thinkpad p51scope:ltversion:6.0.8904.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m715t\/sscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkpad t580scope:ltversion:6.0.8882.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m6600t\/sscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:v510z \scope:ltversion:6.0.8881.1

Trust: 1.0

vendor:lenovomodel:thinkpad t450scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:yangtian ytm6900e-00scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkpad t460sscope:ltversion:6.0.8882.1

Trust: 1.0

vendor:lenovomodel:thinkpad l390 yogascope:ltversion:6.0.8757.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m7300zscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m9500zscope:ltversion:6.0.8881.1

Trust: 1.0

vendor:lenovomodel:thinkpad t460pscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:ideacentre 610s-02ishscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:ideacentre 310-15iapscope: - version: -

Trust: 0.8

vendor:lenovomodel:ideacentre 510s-08iklscope: - version: -

Trust: 0.8

vendor:lenovomodel:ideacentre 300s-11ishscope: - version: -

Trust: 0.8

vendor:lenovomodel:ideacentre 510-15iklscope: - version: -

Trust: 0.8

vendor:lenovomodel:ideacentre 310a-15iapscope: - version: -

Trust: 0.8

vendor:lenovomodel:ideacentre 310s-08iapscope: - version: -

Trust: 0.8

vendor:lenovomodel:ideacentre 510-15abrscope: - version: -

Trust: 0.8

vendor:lenovomodel:ideacentre 610s-02ishscope: - version: -

Trust: 0.8

vendor:lenovomodel:ideacentre 510s-08ishscope: - version: -

Trust: 0.8

vendor:lenovomodel:ideacentre 310-15asrscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2020-017572 // NVD: CVE-2019-19705

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2019-19705
value: HIGH

Trust: 1.0

NVD: CVE-2019-19705
value: HIGH

Trust: 0.8

CNNVD: CNNVD-202003-578
value: HIGH

Trust: 0.6

nvd@nist.gov: CVE-2019-19705
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.1

Trust: 1.0

NVD: CVE-2019-19705
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2020-017572 // CNNVD: CNNVD-202003-578 // NVD: CVE-2019-19705

PROBLEMTYPE DATA

problemtype:CWE-428

Trust: 1.0

problemtype:unquoted search path or element (CWE-428) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2020-017572 // NVD: CVE-2019-19705

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-202003-578

TYPE

code problem

Trust: 0.6

sources: CNNVD: CNNVD-202003-578

PATCH

title:LEN-30506url:https://support.lenovo.com/us/en/product_security/ps500315-realtek-audio-driver-vulnerability

Trust: 0.8

title:Realtek Audio Driver Security vulnerabilitiesurl:http://123.124.177.30/web/xxk/bdxqById.tag?id=112246

Trust: 0.6

title:HP: HPSBHF03665 rev. 1 - Realtek Audio Driver Security Updateurl:https://vulmon.com/vendoradvisory?qidtp=hp_bulletin&qid=HPSBHF03665

Trust: 0.1

title:BleepingComputerurl:https://www.bleepingcomputer.com/news/security/realtek-fixes-dll-hijacking-flaw-in-hd-audio-driver-for-windows/

Trust: 0.1

sources: VULMON: CVE-2019-19705 // JVNDB: JVNDB-2020-017572 // CNNVD: CNNVD-202003-578

EXTERNAL IDS

db:NVDid:CVE-2019-19705

Trust: 3.3

db:JVNDBid:JVNDB-2020-017572

Trust: 0.8

db:LENOVOid:LEN-30506

Trust: 0.6

db:CNNVDid:CNNVD-202003-578

Trust: 0.6

db:VULMONid:CVE-2019-19705

Trust: 0.1

sources: VULMON: CVE-2019-19705 // JVNDB: JVNDB-2020-017572 // CNNVD: CNNVD-202003-578 // NVD: CVE-2019-19705

REFERENCES

url:https://support.lenovo.com/us/en/product_security/ps500315-realtek-audio-driver-vulnerability

Trust: 1.6

url:https://nvd.nist.gov/vuln/detail/cve-2019-19705

Trust: 0.8

url:https://cxsecurity.com/cveshow/cve-2019-19705/

Trust: 0.6

url:https://support.lenovo.com/us/en/product_security/len-30506

Trust: 0.6

url:https://www.bleepingcomputer.com/news/security/realtek-fixes-dll-hijacking-flaw-in-hd-audio-driver-for-windows/

Trust: 0.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/177491

Trust: 0.1

url:https://support.hp.com/us-en/document/c06622884

Trust: 0.1

sources: VULMON: CVE-2019-19705 // JVNDB: JVNDB-2020-017572 // CNNVD: CNNVD-202003-578 // NVD: CVE-2019-19705

SOURCES

db:VULMONid:CVE-2019-19705
db:JVNDBid:JVNDB-2020-017572
db:CNNVDid:CNNVD-202003-578
db:NVDid:CVE-2019-19705

LAST UPDATE DATE

2024-08-14T15:43:22.356000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2020-017572date:2023-04-07T02:31:00
db:CNNVDid:CNNVD-202003-578date:2023-01-09T00:00:00
db:NVDid:CVE-2019-19705date:2023-01-06T14:22:16.630

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2020-017572date:2023-04-07T00:00:00
db:CNNVDid:CNNVD-202003-578date:2020-03-10T00:00:00
db:NVDid:CVE-2019-19705date:2022-12-26T21:15:10.437