NVIDIA Windows GPU Display Driver Vulnerability in Quadro, NVS, and GeForce Products
CVE-2016-8810
7.8HIGH
Key Information:
- Vendor
- Nvidia
- Vendor
- CVE Published:
- 8 November 2016
Summary
A vulnerability in the NVIDIA Windows GPU Display Driver affects Quadro, NVS, and GeForce products by improperly validating user input passed to the driver. This issue arises in the kernel mode layer (nvlddmkm.sys) when handling the DxgDdiEscape ID 0x100009a. An attacker could exploit this flaw to manipulate the internal array index, potentially resulting in a denial of service or escalation of privileges.
Affected Version(s)
Quadro, NVS, and GeForce (all ) Quadro, NVS, and GeForce (all versions)
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved