CVE-2025-11772: Synaptics Fingerprint Driver
Medium severity, CVSS 6.6. EPSS: 0.2% chance of exploitation in the next 30 days.
A carefully crafted DLL, copied to C:\ProgramData\Synaptics folder, allows a local user to execute arbitrary code with elevated privileges during driver installation.
Affected products
- Synaptics Synaptics Fingerprint Driver: from 5.5.3521.1066, before 5.5.3537.1066 (fixed in 5.5.3537.1066); from 5.5.4012.1052, before 5.5.4022.1052 (fixed in 5.5.4022.1052)
Published 2025-12-01. Last modified 2026-06-17.