Elevation of Privilege Vulnerability in NVIDIA GPU Driver for Android
CVE-2017-6264
7.8HIGH
Summary
An elevation of privilege vulnerability has been identified in the NVIDIA GPU driver, specifically in the function gm20b_clk_throt_set_cdev_state. This vulnerability allows a local attacker to exploit an out of bound memory read, potentially executing arbitrary code in the kernel context. Attackers may leverage this to perform unauthorized actions within privileged processes on affected Android devices, posing significant risks to system integrity and security.
Affected Version(s)
Android
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved