Elevation of Privilege Vulnerability in NVIDIA GPU Driver for Android
CVE-2017-6264

7.8HIGH

Key Information:

Vendor
Nvidia
Status
Vendor
CVE Published:
6 November 2017

Summary

An elevation of privilege vulnerability has been identified in the NVIDIA GPU driver, specifically in the function gm20b_clk_throt_set_cdev_state. This vulnerability allows a local attacker to exploit an out of bound memory read, potentially executing arbitrary code in the kernel context. Attackers may leverage this to perform unauthorized actions within privileged processes on affected Android devices, posing significant risks to system integrity and security.

Affected Version(s)

Android

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.