Impact
A vulnerability in the ELAN TrackPoint driver allows an out‑of‑bounds write that can trigger a system crash when executed by a local, authenticated user. The flaw is a classic out‑of‑bounds write, classified as CWE‑125, which results in a denial‑of‑service condition rather than privilege escalation or data exposure.
Affected Systems
Affected devices include Lenovo ThinkPad and consumer laptops that use the ELAN TrackPoint or ClickPad drivers for Windows 11, as detailed in the CNA data.
Risk and Exploitability
The CVSS score of 5.7 indicates a medium severity, and the EPSS score is not available, suggesting no public exploitation has been observed. The flaw requires local, authenticated access and relies on the driver memory layout, so it is unlikely to be exploited from a remote vector. The risk to an organization is primarily the potential for an end‑user to trigger a system crash, interrupting productivity.
OpenCVE Enrichment