Kernel Mode Layer Malfunction in NVIDIA Windows GPU Display Driver
CVE-2019-5666
7.8HIGH
Summary
The NVIDIA Windows GPU Display Driver has a vulnerability in the kernel mode layer (nvlddmkm.sys) related to the DxgkDdiCreateContext command. It improperly handles untrusted input when computing or using an array index, leading to potential denial of service or escalation of privileges. This issue arises from inadequate validation of the index, allowing it to reference invalid array positions, thus exposing the system to security risks. Users of the driver are advised to update to the latest version to mitigate these risks.
Affected Version(s)
NVIDIA GPU Graphics Driver All
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved