CVE-2025-11772: Synaptics Fingerprint Driver

Medium severity, CVSS 6.6. EPSS: 0.2% chance of exploitation in the next 30 days.

A carefully crafted DLL, copied to C:\ProgramData\Synaptics folder, allows a local user to execute arbitrary code with elevated privileges during driver installation.

Affected products

  • Synaptics Synaptics Fingerprint Driver: from 5.5.3521.1066, before 5.5.3537.1066 (fixed in 5.5.3537.1066); from 5.5.4012.1052, before 5.5.4022.1052 (fixed in 5.5.4022.1052)

Published 2025-12-01. Last modified 2026-06-17.