Back

HIGH

Privilege Escalation Vulnerability in CxUIUSvc service

Published Mar 11, 2025

Description

** UNSUPPORTED WHEN ASSIGNED ** 

A privilege escalation vulnerability in CxUIUSvc64.exe and CxUIUSvc32.exe of Synaptics audio drivers allows a local authorized attacker to load a DLL in a privileged process.

Out of an abundance of caution, this CVE ID is being assigned to better serve our customers and ensure all who are still running this product understand that the product is End-of-Life and should be removed. For more information on this, refer to the CVE Record’s reference information.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner Synaptics
Published Mar 11, 2025
Updated Mar 11, 2025
Reserved Sep 24, 2024

CISA Vulnrichment

Updated Mar 11, 2025

NVD

Status Deferred
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner Synaptics
Published Mar 11, 2025
Updated Mar 11, 2025

GitHub

No data