{"api_version":"1","generated_at":"2026-07-23T09:07:20+00:00","cve":"CVE-2017-3757","urls":{"html":"https://cve.report/CVE-2017-3757","api":"https://cve.report/api/cve/CVE-2017-3757.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-3757","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-3757"},"summary":{"title":"CVE-2017-3757","description":"An unquoted service path vulnerability was identified in the driver for the ElanTech Touchpad, various versions, used on some Lenovo brand notebooks (not ThinkPads). This could allow an attacker with local privileges to execute code with administrative privileges.","state":"PUBLIC","assigner":"psirt@lenovo.com","published_at":"2017-08-29 01:35:00","updated_at":"2017-09-12 15:49:00"},"problem_types":["CWE-428"],"metrics":[],"references":[{"url":"https://support.lenovo.com/us/en/product_security/LEN-14390","name":"https://support.lenovo.com/us/en/product_security/LEN-14390","refsource":"CONFIRM","tags":["Patch","Vendor Advisory"],"title":"Unquoted Service Path Privilege Escalation in ElanTech Touchpad Driver - Lenovo Support US","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-3757","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-3757","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"3757","vulnerable":"1","versionEndIncluding":"11.4.1.6","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"elan_touchpad_driver","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"psirt@lenovo.com","DATE_PUBLIC":"2017-08-24T00:00:00","ID":"CVE-2017-3757","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Lenovo ElanTech Touchpad driver","version":{"version_data":[{"version_value":"various versions"}]}}]},"vendor_name":"Lenovo Group Ltd."}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An unquoted service path vulnerability was identified in the driver for the ElanTech Touchpad, various versions, used on some Lenovo brand notebooks (not ThinkPads). This could allow an attacker with local privileges to execute code with administrative privileges."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Privilege escalation"}]}]},"references":{"reference_data":[{"name":"https://support.lenovo.com/us/en/product_security/LEN-14390","refsource":"CONFIRM","url":"https://support.lenovo.com/us/en/product_security/LEN-14390"}]}},"nvd":{"publishedDate":"2017-08-29 01:35:00","lastModifiedDate":"2017-09-12 15:49:00","problem_types":["CWE-428"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":7.2},"severity":"HIGH","exploitabilityScore":3.9,"impactScore":10,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:emc:elan_touchpad_driver:*:*:*:*:*:*:*:*","versionEndIncluding":"11.4.1.6","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"3757","Ordinal":"100139","Title":"CVE-2017-3757","CVE":"CVE-2017-3757","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"3757","Ordinal":"1","NoteData":"An unquoted service path vulnerability was identified in the driver for the ElanTech Touchpad, various versions, used on some Lenovo brand notebooks (not ThinkPads). This could allow an attacker with local privileges to execute code with administrative privileges.","Type":"Description","Title":null},{"CveYear":"2017","CveId":"3757","Ordinal":"2","NoteData":"2017-08-28","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"3757","Ordinal":"3","NoteData":"2017-08-28","Type":"Other","Title":"Modified"}]}}}