Vulnerability in NVIDIA Windows GPU Display Driver - Quadro, NVS, and GeForce Products
CVE-2016-7381

7.8HIGH

Key Information:

Vendor
Nvidia
Vendor
CVE Published:
8 November 2016

Summary

The NVIDIA Windows GPU Display Driver, specifically versions R340 before 342.00 and R375 before 375.63, contains a vulnerability in its kernel mode layer (nvlddmkm.sys). The issue arises from improper bounds checking on user input when indexing an array in the DxgDdiEscape function. This flaw can lead to denial of service scenarios or potentially allow unauthorized users to escalate their privileges on affected systems, posing significant risks to system security and stability.

Affected Version(s)

Quadro, NVS, and GeForce (all ) Quadro, NVS, and GeForce (all versions)

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.