CVE-2024-9157
Severity CVSS v4.0:
Pending analysis
Type:
CWE-284
Improper Access Control
Publication date:
11/03/2025
Last modified:
11/03/2025
Description
** UNSUPPORTED WHEN ASSIGNED ** <br />
<br />
A privilege escalation vulnerability in CxUIUSvc64.exe and<br />
CxUIUSvc32.exe of Synaptics audio drivers allows a local authorized<br />
attacker to load a DLL in a privileged process.<br />
<br />
<br />
Out of an abundance of caution, this CVE ID is being<br />
assigned to better serve our customers and ensure all who are still running<br />
this product understand that the product is End-of-Life and should be removed.<br />
For more information on this, refer to the CVE Record’s reference information.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH



