CVE-2026-18909
Received Received - Intake

Stack-Based Buffer Overflow in ELAN Smart-Pad on Windows

Vulnerability report for CVE-2026-18909, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-06

Last updated on: 2026-08-06

Assigner: ELAN Microelectronics

Description

A stack-based buffer overflow vulnerability exists in ELAN Microelectronics Corp. ELAN Smart-Pad on Windows (ETD.sys and ETDSMBus.sys). During Intel SMBus recovery, ETDSMBus.sys does not enforce an upper-bound check on the hardware-derived report count, allowing an out-of-range value to be forwarded to ETD.sys where it is used as a loop counter for a stack buffer copy without destination size validation. A local attacker with standard user privileges can trigger a kernel bugcheck (BSOD 0xF7 DRIVER_OVERRAN_STACK_BUFFER), resulting in denial of service. This issue affects ELAN Smart-Pad through ETD24.21.52.3.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-06
Last Modified
2026-08-06
Generated
2026-08-06
AI Q&A
2026-08-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
elan_microelectronics elan_smart-pad 24.21.52.3

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-121 A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stack-based buffer overflow in ELAN Microelectronics Corp. ELAN Smart-Pad drivers (ETD.sys and ETDSMBus.sys) on Windows. During Intel SMBus recovery, the driver fails to validate a hardware-derived report count, allowing an out-of-range value to be used as a loop counter for copying data to a stack buffer without size checks. This can crash the system with a BSOD (0xF7 DRIVER_OVERRAN_STACK_BUFFER).

Detection Guidance

This vulnerability is specific to ELAN Smart-Pad drivers (ETD.sys and ETDSMBus.sys) on Windows. Detection requires checking for the presence of vulnerable driver versions and monitoring for kernel crashes (BSOD 0xF7). Inspect driver files in C:\Windows\System32\drivers\ for ETD.sys and ETDSMBus.sys and verify versions against the affected range (ETD24.21.52.3 or earlier).

Impact Analysis

A local attacker with standard user privileges could trigger this flaw, causing a system crash (BSOD) and denial of service. It does not allow code execution or data theft but disrupts system availability.

Mitigation Strategies

Update ELAN Smart-Pad drivers to the latest version (ETD24.21.52.3 or newer) from the official vendor website. If no update is available, disable the ELAN Smart-Pad driver temporarily via Device Manager or uninstall the device until a patch is released. Monitor for BSOD events as a sign of exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18909. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart