CVE-2017-3757: Emc Elan Touchpad Driver

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

An unquoted service path vulnerability was identified in the driver for the ElanTech Touchpad, various versions, used on some Lenovo brand notebooks (not ThinkPads). This could allow an attacker with local privileges to execute code with administrative privileges.

Affected products

  • Emc Elan Touchpad Driver: up to and including 11.4.1.6

Published 2017-08-29. Last modified 2026-06-17.