Local Service Provider Vulnerability in NVIDIA GeForce Experience and Windows GPU Display Driver
CVE-2019-5695
6.5MEDIUM
Key Information:
- Vendor
Nvidia
- Vendor
- CVE Published:
- 12 November 2019
What is CVE-2019-5695?
A local service provider vulnerability exists in NVIDIA GeForce Experience (versions prior to 3.20.1) and all versions of Windows GPU Display Driver. Attackers with local system and privileged access may exploit this flaw by improperly loading Windows system DLLs without proper path or signature validation. This vulnerability can lead to potential code execution, resulting in denial of service or information disclosure.
Affected Version(s)
NVIDIA GeForce Experience prior to 3.20.1
NVIDIA Windows GPU Display Driver all versions