Kernel Mode Layer Vulnerability in NVIDIA Graphics Driver
CVE-2016-8805
Key Information:
- Vendor
Nvidia
- Vendor
- CVE Published:
- 8 November 2016
Badges
What is CVE-2016-8805?
A vulnerability exists in the NVIDIA Windows GPU Display Driver affecting various Quadro, NVS, and GeForce products. The vulnerability lies in the kernel mode layer (nvlddmkm.sys) where a specific value passed from the user is utilized without proper validation. This oversight allows for the possibility of user-controlled values to access an internal array, which could lead to denial of service or potentially escalating privileges, making systems susceptible to unauthorized access.
Affected Version(s)
Quadro, NVS, and GeForce (all ) Quadro, NVS, and GeForce (all versions)
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.