ID

VAR-202003-1805


CVE

CVE-2019-19705


TITLE

plural  Lenovo  Vulnerability with unquoted search paths or elements in the product

Trust: 0.8

sources: JVNDB: JVNDB-2020-017572

DESCRIPTION

Realtek Audio Drivers for Windows, as used on the Lenovo ThinkPad X1 Carbon 20A7, 20A8, 20BS, and 20BT before 6.0.8882.1 and 20KH and 20KG before 6.0.8907.1 (and on many other Lenovo and non-Lenovo products), mishandles DLL preloading. plural Lenovo The product contains an unquoted search path or element vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. Multiple Lenovo products could allow a local malicious user to execute arbitrary code on the system, caused by a DLL preloading issue in Realtek Audio Drivers. By placing a specially crafted file, an attacker could exploit this vulnerability to execute arbitrary ode on the system

Trust: 1.71

sources: NVD: CVE-2019-19705 // JVNDB: JVNDB-2020-017572 // VULMON: CVE-2019-19705

AFFECTED PRODUCTS

vendor:lenovomodel:thinkpad a275scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m7300zscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:yangtian afq150scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkstation p318scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkserver ts150scope:ltversion:6.0.1.7525

Trust: 1.0

vendor:lenovomodel:thinkserver ts550scope:ltversion:6.0.1.7525

Trust: 1.0

vendor:lenovomodel:thinkpad x1 tabletscope:ltversion:6.0.8907.1

Trust: 1.0

vendor:lenovomodel:ideacentre 510s-08ishscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:yangtian ytm6900e-00scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:yangtian s4150scope:ltversion:6.0.8881.1

Trust: 1.0

vendor:lenovomodel:thinkpad t470sscope:ltversion:6.0.8777.1

Trust: 1.0

vendor:lenovomodel:thinkpad t480scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m910zscope:ltversion:6.0.8881.1

Trust: 1.0

vendor:lenovomodel:thinkpad yoga 11e 3rd genscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkpad t560scope:ltversion:6.0.8882.1

Trust: 1.0

vendor:lenovomodel:thinkpad t570scope:ltversion:6.0.8882.1

Trust: 1.0

vendor:lenovomodel:ideacentre 510-15abrscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:ideacentre 300s-11ishscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkserver ts140scope:ltversion:6.0.1.7016

Trust: 1.0

vendor:lenovomodel:thinkpad t460scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkpad s3 3rd genscope:ltversion:6.0.8882.1

Trust: 1.0

vendor:lenovomodel:thinkpad p50scope:ltversion:6.0.8882.1

Trust: 1.0

vendor:lenovomodel:thinkpad x250scope:ltversion:6.0.8882.1

Trust: 1.0

vendor:lenovomodel:yangtian mc h110 pciscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:ideacentre 310-15asrscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkpad l380 yogascope:ltversion:6.0.8882.1

Trust: 1.0

vendor:lenovomodel:aio520-22iklscope:ltversion:6.0.8881.1

Trust: 1.0

vendor:lenovomodel:aio300-23isuscope:ltversion:6.0.8881.1

Trust: 1.0

vendor:lenovomodel:thinkpad t450scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkpad t480sscope:ltversion:6.0.8907.1

Trust: 1.0

vendor:lenovomodel:legion y720t amdscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkcentre x1 aioscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkstation p320scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:ideacentre 310-15iapscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:yta8900fscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkpad x280scope:ltversion:6.0.8882.1

Trust: 1.0

vendor:lenovomodel:legion y520t z370scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkpad l470scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:v320-15iapscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:ideacentre 310a-15iapscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m6600t\/sscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m710escope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:v510z \scope:ltversion:6.0.8881.1

Trust: 1.0

vendor:lenovomodel:thinkpad x260scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m910qscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkpad l13 yogascope:ltversion:9.0.280.80

Trust: 1.0

vendor:lenovomodel:thinkpad t470scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m6600scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m800scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkpad s2 yoga 4th genscope:ltversion:6.0.8757.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m700qscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkpad l390 yogascope:ltversion:6.0.8757.1

Trust: 1.0

vendor:lenovomodel:thinkpad t460pscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkpad p71scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkpad x270scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkpad t450sscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkpad yoga 11e 4th genscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkstation p310scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:yangtian afh110scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m6600qscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m700zscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkpad x1 tabletscope:ltversion:6.0.8882.1

Trust: 1.0

vendor:lenovomodel:ideacentre 720-18asrscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m715t\/sscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:sydney e3 h110scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:aio510-22ishscope:ltversion:6.0.8881.1

Trust: 1.0

vendor:lenovomodel:legion y720 towerscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkpad p50sscope:ltversion:6.0.8882.1

Trust: 1.0

vendor:lenovomodel:thinkpad t460sscope:ltversion:6.0.8882.1

Trust: 1.0

vendor:lenovomodel:ideacentre 510s-08iklscope:ltversion:6.0.8923.1

Trust: 1.0

vendor:lenovomodel:thinkpad p51sscope:ltversion:6.0.8882.1

Trust: 1.0

vendor:lenovomodel:aio720-24ikbscope:ltversion:6.0.8881.1

Trust: 1.0

vendor:lenovomodel:thinkpad l560scope:ltversion:6.0.8899.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m9550zscope:ltversion:6.0.8881.1

Trust: 1.0

vendor:lenovomodel:yangtian mc h110scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m700t\/sscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkpad x1 yogascope:ltversion:6.0.8882.1

Trust: 1.0

vendor:lenovomodel:aio510-23ishscope:ltversion:6.0.8881.1

Trust: 1.0

vendor:lenovomodel:thinkstation p330 tinyscope:ltversion:6.0.8923.1

Trust: 1.0

vendor:lenovomodel:thinkpad t470pscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkpad x1 carbonscope:ltversion:6.0.8907.1

Trust: 1.0

vendor:lenovomodel:legion y920 towerscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:ideacentre 700scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m818zscope:ltversion:6.0.8881.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m8300zscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:aio520-24iklscope:ltversion:6.0.8881.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m910xscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m715qscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:ideacentre 610s-02ishscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkserver ts250scope:ltversion:6.0.1.7525

Trust: 1.0

vendor:lenovomodel:aio520-27iklscope:ltversion:6.0.8881.1

Trust: 1.0

vendor:lenovomodel:thinkpad l380scope:ltversion:6.0.8882.1

Trust: 1.0

vendor:lenovomodel:thinkcentre e74sscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:aio520-22ikuscope:ltversion:6.0.8881.1

Trust: 1.0

vendor:lenovomodel:thinkstation p330scope:ltversion:6.0.8923.1

Trust: 1.0

vendor:lenovomodel:ideacentre 310s-08iapscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m900scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m900zscope:ltversion:6.0.8881.1

Trust: 1.0

vendor:lenovomodel:thinkpad l450scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkpad s2 yoga 3rd genscope:ltversion:6.0.8882.1

Trust: 1.0

vendor:lenovomodel:thinkpad p51scope:ltversion:6.0.8904.1

Trust: 1.0

vendor:lenovomodel:thinkpad l580scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkpad t25scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:aio y910-27ishscope:ltversion:6.0.8881.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m800zscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:ideacentre 510-15iklscope:ltversion:6.0.8923.1

Trust: 1.0

vendor:lenovomodel:thinkpad a475scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkstation p320 tinyscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m8600t\/sscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkserver ts450scope:ltversion:6.0.1.7525

Trust: 1.0

vendor:lenovomodel:thinkpad p70scope:ltversion:6.0.8882.1

Trust: 1.0

vendor:lenovomodel:aio310-20iapscope:ltversion:6.0.8881.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m9500zscope:ltversion:6.0.8881.1

Trust: 1.0

vendor:lenovomodel:thinkpad p52sscope:ltversion:6.0.8882.1

Trust: 1.0

vendor:lenovomodel:ideacentre 620s-03iklscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m810zscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:v310z\scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:aio520-24ikuscope:ltversion:6.0.8881.1

Trust: 1.0

vendor:lenovomodel:thinkpad t580scope:ltversion:6.0.8882.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m910 t\/sscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:aio 910-27ishscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m710t\/sscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m8350zscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkpad 13scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkcentre e95zscope:ltversion:6.0.8881.1

Trust: 1.0

vendor:lenovomodel:thinkpad l570scope:ltversion:6.0.8899.1

Trust: 1.0

vendor:lenovomodel:thinkpad l480scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:yangtian me\/we h110scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:thinkpad x1 carbonscope:ltversion:6.0.8882.1

Trust: 1.0

vendor:lenovomodel:thinkcentre m710qscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:yangtian tc\/wc h110 pciscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:ideacentre 520s-23ikuscope:ltversion:6.0.8881.1

Trust: 1.0

vendor:lenovomodel:thinkcentre e74zscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:qt a7400scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:v410z\scope:ltversion:6.0.8881.1

Trust: 1.0

vendor:lenovomodel:thinkserver ts240scope:ltversion:6.0.1.7016

Trust: 1.0

vendor:lenovomodel:thinkpad l460scope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:yangtian mf\/wf h110 pciscope:ltversion:6.0.8924.1

Trust: 1.0

vendor:lenovomodel:ideacentre 310-15iapscope: - version: -

Trust: 0.8

vendor:lenovomodel:ideacentre 510s-08iklscope: - version: -

Trust: 0.8

vendor:lenovomodel:ideacentre 300s-11ishscope: - version: -

Trust: 0.8

vendor:lenovomodel:ideacentre 510-15iklscope: - version: -

Trust: 0.8

vendor:lenovomodel:ideacentre 310a-15iapscope: - version: -

Trust: 0.8

vendor:lenovomodel:ideacentre 310s-08iapscope: - version: -

Trust: 0.8

vendor:lenovomodel:ideacentre 510-15abrscope: - version: -

Trust: 0.8

vendor:lenovomodel:ideacentre 610s-02ishscope: - version: -

Trust: 0.8

vendor:lenovomodel:ideacentre 510s-08ishscope: - version: -

Trust: 0.8

vendor:lenovomodel:ideacentre 310-15asrscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2020-017572 // NVD: CVE-2019-19705

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2019-19705
value: HIGH

Trust: 1.0

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2019-19705
value: HIGH

Trust: 1.0

NVD: CVE-2019-19705
value: HIGH

Trust: 0.8

CNNVD: CNNVD-202003-578
value: HIGH

Trust: 0.6

nvd@nist.gov: CVE-2019-19705
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.1

Trust: 2.0

NVD: CVE-2019-19705
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2020-017572 // CNNVD: CNNVD-202003-578 // NVD: CVE-2019-19705 // NVD: CVE-2019-19705

PROBLEMTYPE DATA

problemtype:CWE-428

Trust: 1.0

problemtype:unquoted search path or element (CWE-428) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2020-017572 // NVD: CVE-2019-19705

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-202003-578

TYPE

code problem

Trust: 0.6

sources: CNNVD: CNNVD-202003-578

PATCH

title:LEN-30506url:https://support.lenovo.com/us/en/product_security/ps500315-realtek-audio-driver-vulnerability

Trust: 0.8

title:Realtek Audio Driver Security vulnerabilitiesurl:http://123.124.177.30/web/xxk/bdxqById.tag?id=112246

Trust: 0.6

title:HP: HPSBHF03665 rev. 1 - Realtek Audio Driver Security Updateurl:https://vulmon.com/vendoradvisory?qidtp=hp_bulletin&qid=HPSBHF03665

Trust: 0.1

title:BleepingComputerurl:https://www.bleepingcomputer.com/news/security/realtek-fixes-dll-hijacking-flaw-in-hd-audio-driver-for-windows/

Trust: 0.1

sources: VULMON: CVE-2019-19705 // JVNDB: JVNDB-2020-017572 // CNNVD: CNNVD-202003-578

EXTERNAL IDS

db:NVDid:CVE-2019-19705

Trust: 3.3

db:JVNDBid:JVNDB-2020-017572

Trust: 0.8

db:LENOVOid:LEN-30506

Trust: 0.6

db:CNNVDid:CNNVD-202003-578

Trust: 0.6

db:VULMONid:CVE-2019-19705

Trust: 0.1

sources: VULMON: CVE-2019-19705 // JVNDB: JVNDB-2020-017572 // CNNVD: CNNVD-202003-578 // NVD: CVE-2019-19705

REFERENCES

url:https://support.lenovo.com/us/en/product_security/ps500315-realtek-audio-driver-vulnerability

Trust: 1.6

url:https://nvd.nist.gov/vuln/detail/cve-2019-19705

Trust: 0.8

url:https://cxsecurity.com/cveshow/cve-2019-19705/

Trust: 0.6

url:https://support.lenovo.com/us/en/product_security/len-30506

Trust: 0.6

url:https://www.bleepingcomputer.com/news/security/realtek-fixes-dll-hijacking-flaw-in-hd-audio-driver-for-windows/

Trust: 0.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/177491

Trust: 0.1

url:https://support.hp.com/us-en/document/c06622884

Trust: 0.1

sources: VULMON: CVE-2019-19705 // JVNDB: JVNDB-2020-017572 // CNNVD: CNNVD-202003-578 // NVD: CVE-2019-19705

SOURCES

db:VULMONid:CVE-2019-19705
db:JVNDBid:JVNDB-2020-017572
db:CNNVDid:CNNVD-202003-578
db:NVDid:CVE-2019-19705

LAST UPDATE DATE

2025-04-15T23:28:46.694000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2020-017572date:2023-04-07T02:31:00
db:CNNVDid:CNNVD-202003-578date:2023-01-09T00:00:00
db:NVDid:CVE-2019-19705date:2025-04-14T17:15:22.570

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2020-017572date:2023-04-07T00:00:00
db:CNNVDid:CNNVD-202003-578date:2020-03-10T00:00:00
db:NVDid:CVE-2019-19705date:2022-12-26T21:15:10.437