Local Privilege Escalation Vulnerability in NVIDIA GPU Driver
CVE-2016-2558
8.4HIGH
Summary
The NVIDIA GPU graphics driver presents a local privilege escalation vulnerability within its Kernel Mode Driver layer, specifically affecting versions R340 prior to 341.95 and R352 prior to 354.74 on Windows systems. This vulnerability could allow local users to exploit untrusted pointers leading to uninitialized or out-of-bounds memory access. Attackers may potentially access sensitive information, trigger system crashes, or escalate privileges, compromising system integrity and user data. For more details, refer to NVIDIA's official support and Lenovo's security advisory.
References
CVSS V3.1
Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved