Binary Planting Vulnerability in NVIDIA GeForce Experience
CVE-2019-5701

7.8HIGH

Key Information:

Vendor
Nvidia
Vendor
CVE Published:
9 November 2019

Summary

NVIDIA GeForce Experience, versions before 3.20.0.118, poses a significant security risk when GameStream is activated. An attacker with local system access can exploit this vulnerability to load unsigned Intel graphics driver DLLs, bypassing path validation and signature checks. This could lead to various malicious outcomes, including denial of service, unauthorized information disclosure, or even privilege escalation resulting in arbitrary code execution. Organizations utilizing this software should take immediate action to update to the latest version to mitigate this risk.

Affected Version(s)

NVIDIA GeForce Experience before 3.20.0.118

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.