Binary Planting Vulnerability in NVIDIA GeForce Experience
CVE-2019-5701
7.8HIGH
Summary
NVIDIA GeForce Experience, versions before 3.20.0.118, poses a significant security risk when GameStream is activated. An attacker with local system access can exploit this vulnerability to load unsigned Intel graphics driver DLLs, bypassing path validation and signature checks. This could lead to various malicious outcomes, including denial of service, unauthorized information disclosure, or even privilege escalation resulting in arbitrary code execution. Organizations utilizing this software should take immediate action to update to the latest version to mitigate this risk.
Affected Version(s)
NVIDIA GeForce Experience before 3.20.0.118
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved